ChainRisk Lens: AI-Powered Software Supply-Chain Investigation from SBOMs A developer built ChainRisk Lens, an open-source tool that ingests CycloneDX SBOMs to construct deterministic dependency graphs, calculate downstream impact, and trace dependency paths for software supply-chain investigations. The Go-based project uses a standard-library-only core and integrates Ollama with an open-weight Gemma model to explain and investigate the deterministic security evidence locally, keeping dependency data off proprietary AI APIs. This is a submission for the Hacktoberfest Weekend Challenge: Build for a Friend https://dev.to/challenges/hacktoberfest-weekend-2026-10-01 I built ChainRisk Lens , an open-source AI-assisted software supply-chain investigation tool. I built it for a friend who works with software dependencies and needs a simpler way to answer: “If this dependency is compromised, what could be affected?” ChainRisk Lens takes a CycloneDX SBOM, builds a deterministic dependency graph, calculates potential downstream impact, traces dependency paths, and uses an open-weight AI model to explain and investigate the evidence. The key idea is simple: deterministic analysis produces the security evidence; AI explains and investigates it. Repository: https://github.com/jijo-OO7/ChainRisk-Lens https://github.com/jijo-OO7/ChainRisk-Lens Example: chainrisk-lens investigate \ testdata/minimal-cyclonedx.json \ --target library@2.3.4 \ --model gemma4:e2b \ --question "What could be affected if this component is compromised?" Code ChainRisk Lens on GitHub The core pipeline is: CycloneDX SBOM ↓ Parser / Normalization ↓ Dependency Graph ↓ Deterministic Impact Analysis ↓ Investigation Evidence ↓ Open-Weight AI ↓ Human / JSON Report ChainRisk Lens is written in Go and uses a standard-library-only core. For AI investigation, I integrated Ollama and designed the model layer to remain provider/model agnostic. The project's default model is Gemma, while other Ollama-compatible models can be selected through --model. The deterministic layer handles: Open-weight AI makes it possible to run the investigation locally rather than requiring users to send their software supply-chain data to a proprietary AI API. It also keeps the architecture flexible: the deterministic analysis does not depend on a particular model, and users can choose an Ollama-compatible model appropriate for their environment. For supply-chain security, keeping control over where dependency information is processed is an important part of the design. Prize Categories