cd /news/ai-tools/chainrisk-lens-ai-powered-software-s… · home › topics › ai-tools › article
[ARTICLE · art-144036] src=dev.to ↗ pub= topic=ai-tools verified=true sentiment=↑ positive

ChainRisk Lens: AI-Powered Software Supply-Chain Investigation from SBOMs

A developer built ChainRisk Lens, an open-source tool that ingests CycloneDX SBOMs to construct deterministic dependency graphs, calculate downstream impact, and trace dependency paths for software supply-chain investigations. The Go-based project uses a standard-library-only core and integrates Ollama with an open-weight Gemma model to explain and investigate the deterministic security evidence locally, keeping dependency data off proprietary AI APIs.

by read1 min views5 publishedOct 2, 2026

This is a submission for the Hacktoberfest Weekend Challenge: Build for a Friend

I built ChainRisk Lens, an open-source AI-assisted software supply-chain investigation tool.

I built it for a friend who works with software dependencies and needs a simpler way to answer:

“If this dependency is compromised, what could be affected?”

ChainRisk Lens takes a CycloneDX SBOM, builds a deterministic dependency graph, calculates potential downstream impact, traces dependency paths, and uses an open-weight AI model to explain and investigate the evidence.

The key idea is simple: deterministic analysis produces the security evidence; AI explains and investigates it.

Repository: https://github.com/jijo-OO7/ChainRisk-Lens

Example:

chainrisk-lens investigate \
  testdata/minimal-cyclonedx.json \
  --target library@2.3.4 \
  --model gemma4:e2b \
  --question "What could be affected if this component is compromised?"

Code
ChainRisk Lens on GitHub
The core pipeline is:
CycloneDX SBOM
      ↓
Parser / Normalization
      ↓
Dependency Graph
      ↓
Deterministic Impact Analysis
      ↓
Investigation Evidence
      ↓
Open-Weight AI
      ↓
Human / JSON Report

ChainRisk Lens is written in Go and uses a standard-library-only core.

For AI investigation, I integrated Ollama and designed the model layer to remain provider/model agnostic. The project's default model is Gemma, while other Ollama-compatible models can be selected through --model.

The deterministic layer handles:

Open-weight AI makes it possible to run the investigation locally rather than requiring users to send their software supply-chain data to a proprietary AI API.

It also keeps the architecture flexible: the deterministic analysis does not depend on a particular model, and users can choose an Ollama-compatible model appropriate for their environment.

For supply-chain security, keeping control over where dependency information is processed is an important part of the design.

Prize Categories

── more in #ai-tools 4 stories · sorted by recency
── more on @chainrisk lens 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/chainrisk-lens-ai-po…] indexed:0 read:1min 2026-10-02 · —