{
  "id": 11489777,
  "title": "ChainRisk Lens: AI-Powered Software Supply-Chain Investigation from SBOMs",
  "url": "https://urgent.news/2026/10/02/chainrisk-lens-ai-powered-software-supply-chain-investigation-from",
  "topic": "ai",
  "section": "AI",
  "published": "2026-10-02T17:26:45.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/jijo-007/chainrisk-lens-ai-powered-software-supply-chain-investigation-from-sboms-57b9"
  },
  "original_language": "en",
  "account": null,
  "summary": "ChainRisk Lens is an open-source AI-assisted software supply-chain investigation tool created by a developer who built it for a friend in the software dependency space. The tool takes a CycloneDX SBOM, builds a deterministic dependency graph, calculates potential downstream impact, traces dependency paths, and uses an open-weight AI model to explain and investigate the evidence. ChainRisk Lens is written in Go and uses a standard-library-only core, with the AI investigation layer integrated using Ollama and designed to be provider/model agnostic. The default model is Gemma, but other Ollama-compatible models can be selected through a command-line flag. The project emphasizes open innovation by keeping security facts deterministic and allowing users to run the investigation locally without sending their supply-chain data to a proprietary AI API.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}