This is a submission for the Hacktoberfest Weekend Challenge: Build for a Friend
I built ChainRisk Lens, an open-source AI-assisted software supply-chain investigation tool.
I built it for a friend who works with software dependencies and needs a simpler way to answer:
“If this dependency is compromised, what could be affected?”
ChainRisk Lens takes a CycloneDX SBOM, builds a deterministic dependency graph, calculates potential downstream impact, traces dependency paths, and uses an open-weight AI model to explain and investigate the evidence.
The key idea is simple: deterministic analysis produces the security evidence; AI explains and investigates it.
Repository: https://github.com/jijo-OO7/ChainRisk-Lens
Example:
chainrisk-lens investigate \
testdata/minimal-cyclonedx.json \
--target library@2.3.4 \
--model gemma4:e2b \
--question "What could be affected if this component is compromised?"
Code
ChainRisk Lens on GitHub
The core pipeline is:
CycloneDX SBOM
↓
Parser / Normalization
↓
Dependency Graph
↓
Deterministic Impact Analysis
↓
Investigation Evidence
↓
Open-Weight AI
↓
Human / JSON Report
ChainRisk Lens is written in Go and uses a standard-library-only core.
For AI investigation, I integrated Ollama and designed the model layer to remain provider/model agnostic. The project's default model is Gemma, while other Ollama-compatible models can be selected through --model.
The deterministic layer handles:
Open-weight AI makes it possible to run the investigation locally rather than requiring users to send their software supply-chain data to a proprietary AI API.
It also keeps the architecture flexible: the deterministic analysis does not depend on a particular model, and users can choose an Ollama-compatible model appropriate for their environment.
For supply-chain security, keeping control over where dependency information is processed is an important part of the design.
Prize Categories