Know the moment a component in your software becomes a risk, not days later on social media
Modern applications are assembled from thousands of open-source components, and AI coding tools now pull them in faster than anyone can vet.
ChainGarde inventories every component in your software and re-checks it daily against public vulnerability advisories, so a newly disclosed or compromised package surfaces against your exact versions right away.
Common challenges
Nobody chooses every dependency anymore. AI coding assistants pull libraries into your codebase during development, with no security-aware decision behind them.
What we consistently see:
AI tools are choosing your dependencies
Everyone is a development shop now
Severity alone is noise
Disclosure moves faster than teams hear
Everyone is a development shop now. If your teams generate code, even with AI tools, you are shipping software supply-chain risk, whether or not you think of yourselves that way.
A high severity score doesn't tell you whether a flaw is actually being exploited. Teams burn time on findings that don't matter and miss the ones that do. And when a package is compromised, teams often hear about it from social media days after it hit the public advisory feeds.
How ChainGarde works
Six steps that run continuously, so findings always reflect the code you are shipping today.
Connect your repository
ChainGarde connects to your repository with an API key
Inventory your components
ChainGarde ingests your application's CycloneDX SBOM, a full inventory of the software components used to build it
Match daily against public advisories
Every component is re-checked against public vulnerability data, every day
Score by real risk, not just severity
Raw severity is combined with CISA's Known Exploited Vulnerabilities catalog (is it being attacked right now) and EPSS (the probability of future exploitation)
Alert on what crosses your threshold
You set the risk tolerance, and escalation timelines agreed up front drive urgency: a defined window for a routine finding, an immediate call for a critical one
Re-check continuously
Every new push to the repository triggers a fresh scan, so findings always reflect your current code
A vulnerability can be severe but unlikely to be exploited, like a defect with a low failure rate that is catastrophic on the rare occasion it happens.
Severity and likelihood are two different questions
Risk scoring combines three signals, shown side by side.
Severity
Active exploitation (KEV)
Likelihood (EPSS)
Showing severity and likelihood side by side lets your team set its own risk tolerance instead of chasing every high-severity flag. ChainGarde identifies the at-risk component and explains why it matters; how to remediate stays in your engineering team's hands.
Built for any organization writing or generating code, including teams using AI coding tools that don't think of themselves as a development shop but are producing software all the same. Getting started is straightforward: connect ChainGarde to your repository with an API key.
A real example: the TanStack compromise
Early warning on a supply-chain compromise, matched to your exact package versions.
When the May 2026 TanStack supply-chain compromise hit the public advisory feeds, with more than 40 packages compromised through a GitHub Actions weakness, the difference for an organization already running ChainGarde is simple. The daily re-match surfaces the compromise against the exact package versions in your applications and triggers an alert, instead of the team learning about it from social media days later.
SecurIT360 runs ChainGarde against its own software: roughly 43,000 components across dozens of internally built tools produced in the last 18 months, most of it work no one would have called "development" two years ago.