DEV Community

Cover image for ChainRisk Lens: AI-Powered Software Supply-Chain Investigation from SBOMs
Suman Mandal
Suman Mandal

Posted on

ChainRisk Lens: AI-Powered Software Supply-Chain Investigation from SBOMs

Hacktoberfest Weekend Challenge: Build for a Friend Submission 🤝

This is a submission for the Hacktoberfest Weekend Challenge: Build for a Friend

What I Built

I built ChainRisk Lens, an open-source AI-assisted software supply-chain investigation tool.

I built it for a friend who works with software dependencies and needs a simpler way to answer:

“If this dependency is compromised, what could be affected?”

ChainRisk Lens takes a CycloneDX SBOM, builds a deterministic dependency graph, calculates potential downstream impact, traces dependency paths, and uses an open-weight AI model to explain and investigate the evidence.

The key idea is simple: deterministic analysis produces the security evidence; AI explains and investigates it.

Demo

Repository: https://github.com/jijo-OO7/ChainRisk-Lens

Example:

chainrisk-lens investigate \
  testdata/minimal-cyclonedx.json \
  --target library@2.3.4 \
  --model gemma4:e2b \
  --question "What could be affected if this component is compromised?"

Code
ChainRisk Lens on GitHub
The core pipeline is:
CycloneDX SBOM
      ↓
Parser / Normalization
      ↓
Dependency Graph
      ↓
Deterministic Impact Analysis
      ↓
Investigation Evidence
      ↓
Open-Weight AI
      ↓
Human / JSON Report
Enter fullscreen mode Exit fullscreen mode

How I Built It

ChainRisk Lens is written in Go and uses a standard-library-only core.
For AI investigation, I integrated Ollama and designed the model layer to remain provider/model agnostic. The project's default model is Gemma, while other Ollama-compatible models can be selected through --model.

The deterministic layer handles:

  • SBOM parsing and validation
  • dependency graph construction
  • impact analysis
  • dependency paths
  • cycle detection
  • evidence validation The AI layer receives that validated evidence and is instructed not to invent CVEs, vulnerabilities, severity, exploitability, affected versions, or remediation facts. This keeps the security facts deterministic while using AI for investigation and explanation.

Why Does Open Innovation Matter?

Open-weight AI makes it possible to run the investigation locally rather than requiring users to send their software supply-chain data to a proprietary AI API.
It also keeps the architecture flexible: the deterministic analysis does not depend on a particular model, and users can choose an Ollama-compatible model appropriate for their environment.
For supply-chain security, keeping control over where dependency information is processed is an important part of the design.

Prize Categories

  • Best Use of Gemma — ChainRisk Lens uses Gemma as its default open-weight AI investigation model.
  • Best Use of GitHub Copilot — Copilot was used extensively during implementation, testing, review, and refinement of the project.

Top comments (0)