Untitled Project · Current
● SAVED

Supply-Chain Overview

What is in this software? What changed? What deserves review?

Highest Priority Findings

Recent Supply-Chain Changes

Ecosystem Distribution

License Distribution

Review Progress

Imported Evidence

Files are treated as data only. CHAINLINK never executes package scripts or imported code.

Drop software supply-chain evidence hereCycloneDX JSON/XML · SPDX JSON/tag-value/YAML · npm/Yarn/pnpm · Python · Rust · Go · Maven/Gradle · NuGet · Composer · Bundler · firmware CSV/JSON/YAML · vulnerability JSON/CSV

Source File Registry

Parser Diagnostics & Document Metadata

Click any source-file row for its complete parser record, schema evidence, document metadata, warnings, and local SHA-256.

Revision Intelligence

Preserve releases, reconstruct historical builds, inspect component lifecycles, and compare any two saved states.

Saved revision snapshots are preserved as project evidence. Loading a snapshot reconstructs its component inventory and dependency graph into the working Current or Baseline dataset.

Release Timeline

Compare Any Two Revisions

Supply-Chain Churn

Components with the most presence, version, source, license, supplier, namespace, or checksum transitions across saved releases.

Component History

Component Inventory

Normalized component records with dependency, provenance, licensing, maintenance, security, and review context.

Dependency Impact

Explain why a component is present, who consumes it, and how far a change can propagate.

Select a component to calculate consumers, root paths, introducers, descendants, and blast radius.

Dependency Graph

Interactive graph with ancestry, descendant, runtime, change, vulnerability, and criticality filters.

Select a graph node to inspect its dependency context.

Dependency Tree

Expandable hierarchy with path-to-root, consumer, and impact context.

Provenance Chain

Trace each component from product context through supplier, acquisition source, artifact identity, checksum evidence, and imported source record.

Sources & Provenance

Source-oriented inventory for acquisition paths, suppliers, imported hashes, and evidence files.

Binary / Closed Component Registry

First-class evidence records for vendor binaries, precompiled libraries, firmware blobs, and other components whose source may not be available.

Engineer enrichment updates normalized fields while the original imported record remains available in Raw Source. A completed registry entry is evidence documentation, not proof that a binary is trustworthy.

License Workbench 2.0

Inspect declared license evidence, parse SPDX expressions, identify ambiguous declarations, and apply local review profiles. CHAINLINK is not a substitute for legal advice.

Distribution

Project License Policy Profile

Policy states describe your local review workflow. CHAINLINK does not label licenses “safe” or “unsafe” and does not provide legal conclusions.

Add Review Category

Findings

Deterministic, explainable analysis. Severity and confidence are separate.

Analysis Rule Registry

Every automated finding maps to a named, versioned rule with explicit defaults and purpose.

Integrity Analysis

Checksum, provenance, supplier, namespace, and source-type changes are surfaced as evidence—not accusations.

Current Evidence Conflicts

Revision Integrity Changes

Vulnerability Workbench 2.0

Import OSV, NVD-derived JSON, CycloneDX vulnerability/VEX, CSAF, or custom advisory CSV/JSON; evaluate applicability and preserve engineering VEX dispositions.

Imported Intelligence

Engineering Review

Imported advisory status and CHAINLINK applicability are kept separate from the engineer's disposition. A source VEX statement never silently suppresses the underlying advisory.

Maintenance Review

Evidence-driven maintenance state. Old release dates alone do not imply abandonment.

State is derived only from imported maintenance/version metadata.

Supply-Chain Drift

Added, removed, modified, downgraded, source, license, and integrity changes.

Engineering Dispositions

Review conclusions never erase the underlying evidence.

Evidence Ledger

Follow each engineering conclusion back through analysis rules, normalized records, and imported source evidence.

The ledger is a traceability index. It does not replace the original imported record, advisory, finding, or human review record.

Review History

Chronological audit trail of component reviews, finding dispositions, VEX decisions, binary evidence edits, release exceptions, release decisions, and sign-off changes.

Release Review

Advisory release assurance based on imported evidence, CHAINLINK analysis, local policy, documented exceptions, and human review.

Release Assessment

CHAINLINK release assurance is advisory engineering evidence. It does not certify software, replace organizational approval, or guarantee security.

Decision Record

Release Checks

Click a failed check to document or clear a release exception.

Decision History

Policy Profiles

Optional local rules produce findings; they do not block import.

Profile

Custom Rule

Policy findings remain advisory unless you explicitly integrate CHAINLINK into a separate release process.

Review Sign-Off

Records reviewer attestation only; it does not imply a cryptographic digital signature.

Reporting Workbench

Generate purpose-built engineering reports from the same traceable project evidence.

Evidence Package 2.0

Export a structured, locally generated ZIP that preserves the project model, evidence ledger, review history, reports, release decisions, revision history, and analysis artifacts.

One-click structured package

CHAINLINK builds the ZIP entirely in your browser with no upload or external service. SHA-256 hashes are generated locally for packaged evidence artifacts where browser cryptography is available.

Individual artifacts

Performance & Scale

Background jobs, storage health, rendering strategy, and large-project controls.

Background Job

No background job is active.

Persistence

Scale Strategy

Large Project Test

Generate a synthetic dependency inventory locally to exercise the 10,000+ component path. This replaces Current only after confirmation.

Production Hardening

Local security guardrails, migration/recovery health, accessibility checks, and release self-tests.

Input Guardrails

Imported files are treated as data only. CHAINLINK rejects XML DTD/entities, YAML tags/anchors/aliases, excessive structured-data nesting, oversized project structures, and prototype-pollution keys.

Local Self-Check

Runs deterministic browser-local checks against the bundled parser and safety boundaries. No project data is transmitted.

Recovery Checkpoints

Create up to three local IndexedDB recovery checkpoints. Checkpoints are full CHAINLINK state copies and are never uploaded.

Accessibility & Responsive Audit

Checks the rendered application for accessible names, duplicate IDs, focus behavior, landmark support, and core mobile affordances.

Self-Check Detail

Run the local self-check to inspect production-hardening checks.

Settings

Local project behavior and interface preferences.

Appearance

Project Controls

Fresh Start

Creates a genuinely empty project and does not reload demo data.

Background job0%
Preparing…