{"slug": "chainrisk-lens-ai-powered-software-supply-chain-investigation-from-sboms", "title": "ChainRisk Lens: AI-Powered Software Supply-Chain Investigation from SBOMs", "summary": "A developer built ChainRisk Lens, an open-source tool that ingests CycloneDX SBOMs to construct deterministic dependency graphs, calculate downstream impact, and trace dependency paths for software supply-chain investigations. The Go-based project uses a standard-library-only core and integrates Ollama with an open-weight Gemma model to explain and investigate the deterministic security evidence locally, keeping dependency data off proprietary AI APIs.", "body_md": "*This is a submission for the [Hacktoberfest Weekend Challenge: Build for a Friend](https://dev.to/challenges/hacktoberfest-weekend-2026-10-01)*\n\nI built **ChainRisk Lens**, an open-source AI-assisted software supply-chain investigation tool.\n\nI built it for a friend who works with software dependencies and needs a simpler way to answer:\n\n**“If this dependency is compromised, what could be affected?”**\n\nChainRisk Lens takes a CycloneDX SBOM, builds a deterministic dependency graph, calculates potential downstream impact, traces dependency paths, and uses an open-weight AI model to explain and investigate the evidence.\n\nThe key idea is simple: **deterministic analysis produces the security evidence; AI explains and investigates it.**\n\n**Repository:** [https://github.com/jijo-OO7/ChainRisk-Lens](https://github.com/jijo-OO7/ChainRisk-Lens)\n\nExample:\n\n```\nchainrisk-lens investigate \\\n  testdata/minimal-cyclonedx.json \\\n  --target library@2.3.4 \\\n  --model gemma4:e2b \\\n  --question \"What could be affected if this component is compromised?\"\n\nCode\nChainRisk Lens on GitHub\nThe core pipeline is:\nCycloneDX SBOM\n      ↓\nParser / Normalization\n      ↓\nDependency Graph\n      ↓\nDeterministic Impact Analysis\n      ↓\nInvestigation Evidence\n      ↓\nOpen-Weight AI\n      ↓\nHuman / JSON Report\n```\n\nChainRisk Lens is written in Go and uses a standard-library-only core.\n\nFor AI investigation, I integrated Ollama and designed the model layer to remain provider/model agnostic. The project's default model is Gemma, while other Ollama-compatible models can be selected through --model.\n\nThe deterministic layer handles:\n\nOpen-weight AI makes it possible to run the investigation locally rather than requiring users to send their software supply-chain data to a proprietary AI API.\n\nIt also keeps the architecture flexible: the deterministic analysis does not depend on a particular model, and users can choose an Ollama-compatible model appropriate for their environment.\n\nFor supply-chain security, keeping control over where dependency information is processed is an important part of the design.\n\nPrize Categories", "url": "https://wpnews.pro/news/chainrisk-lens-ai-powered-software-supply-chain-investigation-from-sboms", "canonical_source": "https://dev.to/jijo-007/chainrisk-lens-ai-powered-software-supply-chain-investigation-from-sboms-57b9", "published_at": "2026-10-02 17:26:45+00:00", "updated_at": "2026-10-02 17:37:24.640973+00:00", "lang": "en", "topics": ["ai-tools", "developer-tools", "ai-agents"], "entities": ["ChainRisk Lens", "Ollama", "Gemma", "CycloneDX", "Go", "GitHub"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/chainrisk-lens-ai-powered-software-supply-chain-investigation-from-sboms", "markdown": "https://wpnews.pro/news/chainrisk-lens-ai-powered-software-supply-chain-investigation-from-sboms.md", "text": "https://wpnews.pro/news/chainrisk-lens-ai-powered-software-supply-chain-investigation-from-sboms.txt", "jsonld": "https://wpnews.pro/news/chainrisk-lens-ai-powered-software-supply-chain-investigation-from-sboms.jsonld"}}