Supply-Chain Overview
What is in this software? What changed? What deserves review?
Highest Priority Findings
Recent Supply-Chain Changes
Ecosystem Distribution
License Distribution
Review Progress
Imported Evidence
Files are treated as data only. CHAINLINK never executes package scripts or imported code.
Source File Registry
Parser Diagnostics & Document Metadata
Click any source-file row for its complete parser record, schema evidence, document metadata, warnings, and local SHA-256.
Revision Intelligence
Preserve releases, reconstruct historical builds, inspect component lifecycles, and compare any two saved states.
Release Timeline
Compare Any Two Revisions
Supply-Chain Churn
Components with the most presence, version, source, license, supplier, namespace, or checksum transitions across saved releases.
Component History
Component Inventory
Normalized component records with dependency, provenance, licensing, maintenance, security, and review context.
Dependency Impact
Explain why a component is present, who consumes it, and how far a change can propagate.
Dependency Graph
Interactive graph with ancestry, descendant, runtime, change, vulnerability, and criticality filters.
Dependency Tree
Expandable hierarchy with path-to-root, consumer, and impact context.
Provenance Chain
Trace each component from product context through supplier, acquisition source, artifact identity, checksum evidence, and imported source record.
Sources & Provenance
Source-oriented inventory for acquisition paths, suppliers, imported hashes, and evidence files.
Binary / Closed Component Registry
First-class evidence records for vendor binaries, precompiled libraries, firmware blobs, and other components whose source may not be available.
License Workbench 2.0
Inspect declared license evidence, parse SPDX expressions, identify ambiguous declarations, and apply local review profiles. CHAINLINK is not a substitute for legal advice.
Distribution
Project License Policy Profile
Add Review Category
Findings
Deterministic, explainable analysis. Severity and confidence are separate.
Analysis Rule Registry
Every automated finding maps to a named, versioned rule with explicit defaults and purpose.
Integrity Analysis
Checksum, provenance, supplier, namespace, and source-type changes are surfaced as evidence—not accusations.
Current Evidence Conflicts
Revision Integrity Changes
Vulnerability Workbench 2.0
Import OSV, NVD-derived JSON, CycloneDX vulnerability/VEX, CSAF, or custom advisory CSV/JSON; evaluate applicability and preserve engineering VEX dispositions.
Imported Intelligence
Engineering Review
Maintenance Review
Evidence-driven maintenance state. Old release dates alone do not imply abandonment.
Supply-Chain Drift
Added, removed, modified, downgraded, source, license, and integrity changes.
Engineering Dispositions
Review conclusions never erase the underlying evidence.
Evidence Ledger
Follow each engineering conclusion back through analysis rules, normalized records, and imported source evidence.
Review History
Chronological audit trail of component reviews, finding dispositions, VEX decisions, binary evidence edits, release exceptions, release decisions, and sign-off changes.
Release Review
Advisory release assurance based on imported evidence, CHAINLINK analysis, local policy, documented exceptions, and human review.
Release Assessment
Decision Record
Decision History
Policy Profiles
Optional local rules produce findings; they do not block import.
Profile
Custom Rule
Review Sign-Off
Records reviewer attestation only; it does not imply a cryptographic digital signature.
Reporting Workbench
Generate purpose-built engineering reports from the same traceable project evidence.
Evidence Package 2.0
Export a structured, locally generated ZIP that preserves the project model, evidence ledger, review history, reports, release decisions, revision history, and analysis artifacts.
One-click structured package
CHAINLINK builds the ZIP entirely in your browser with no upload or external service. SHA-256 hashes are generated locally for packaged evidence artifacts where browser cryptography is available.
Individual artifacts
Performance & Scale
Background jobs, storage health, rendering strategy, and large-project controls.
Background Job
Persistence
Scale Strategy
Large Project Test
Generate a synthetic dependency inventory locally to exercise the 10,000+ component path. This replaces Current only after confirmation.
Production Hardening
Local security guardrails, migration/recovery health, accessibility checks, and release self-tests.
Input Guardrails
Local Self-Check
Runs deterministic browser-local checks against the bundled parser and safety boundaries. No project data is transmitted.
Recovery Checkpoints
Create up to three local IndexedDB recovery checkpoints. Checkpoints are full CHAINLINK state copies and are never uploaded.
Accessibility & Responsive Audit
Checks the rendered application for accessible names, duplicate IDs, focus behavior, landmark support, and core mobile affordances.
Self-Check Detail
Settings
Local project behavior and interface preferences.
Appearance
Project Controls
Creates a genuinely empty project and does not reload demo data.