ChainRisk Lens: AI-Powered Software Supply-Chain Investigation from SBOMs
This is a submission for the Hacktoberfest Weekend Challenge: Build for a Friend What I Built I built ChainRisk Lens , an open-source AI-assisted software supply-chain investigation tool. I built it for a friend who works with software dependencies and needs a simpler way to answer: “If this dependency is compromised, what could be affected?” ChainRisk Lens takes a CycloneDX SBOM, builds a…
ChainRisk Lens is an open-source AI-assisted software supply-chain investigation tool created by a developer who built it for a friend in the software dependency space. The tool takes a CycloneDX SBOM, builds a deterministic dependency graph, calculates potential downstream impact, traces dependency paths, and uses an open-weight AI model to explain and investigate the evidence.
ChainRisk Lens is written in Go and uses a standard-library-only core, with the AI investigation layer integrated using Ollama and designed to be provider/model agnostic. The default model is Gemma, but other Ollama-compatible models can be selected through a command-line flag. The project emphasizes open innovation by keeping security facts deterministic and allowing users to run the investigation locally without sending their supply-chain data to a proprietary AI API.
Brief written by urgent.news from Dev.to's own syndicated text. Machine-written — may contain errors; check the original before relying on it.