Know the moment a component in your software becomes a risk, not days later on social media

Modern applications are assembled from thousands of open-source components, and AI coding tools now pull them in faster than anyone can vet.

ChainGarde inventories every component in your software and re-checks it daily against public vulnerability advisories, so a newly disclosed or compromised package surfaces against your exact versions right away.

Common challenges

Nobody chooses every dependency anymore. AI coding assistants pull libraries into your codebase during development, with no security-aware decision behind them.

What we consistently see:

AI tools are choosing your dependencies

Everyone is a development shop now

Severity alone is noise

Disclosure moves faster than teams hear

Everyone is a development shop now. If your teams generate code, even with AI tools, you are shipping software supply-chain risk, whether or not you think of yourselves that way.

A high severity score doesn't tell you whether a flaw is actually being exploited. Teams burn time on findings that don't matter and miss the ones that do. And when a package is compromised, teams often hear about it from social media days after it hit the public advisory feeds.

How ChainGarde works

Six steps that run continuously, so findings always reflect the code you are shipping today.

Connect your repository

ChainGarde connects to your repository with an API key

Inventory your components

ChainGarde ingests your application's CycloneDX SBOM, a full inventory of the software components used to build it

Match daily against public advisories

Every component is re-checked against public vulnerability data, every day

Score by real risk, not just severity

Raw severity is combined with CISA's Known Exploited Vulnerabilities catalog (is it being attacked right now) and EPSS (the probability of future exploitation)

Alert on what crosses your threshold

You set the risk tolerance, and escalation timelines agreed up front drive urgency: a defined window for a routine finding, an immediate call for a critical one

Re-check continuously

Every new push to the repository triggers a fresh scan, so findings always reflect your current code

A vulnerability can be severe but unlikely to be exploited, like a defect with a low failure rate that is catastrophic on the rare occasion it happens.

Severity and likelihood are two different questions

Risk scoring combines three signals, shown side by side.

Severity

Active exploitation (KEV)

Likelihood (EPSS)

Showing severity and likelihood side by side lets your team set its own risk tolerance instead of chasing every high-severity flag. ChainGarde identifies the at-risk component and explains why it matters; how to remediate stays in your engineering team's hands.

Built for any organization writing or generating code, including teams using AI coding tools that don't think of themselves as a development shop but are producing software all the same. Getting started is straightforward: connect ChainGarde to your repository with an API key.

A real example: the TanStack compromise

Early warning on a supply-chain compromise, matched to your exact package versions.

When the May 2026 TanStack supply-chain compromise hit the public advisory feeds, with more than 40 packages compromised through a GitHub Actions weakness, the difference for an organization already running ChainGarde is simple. The daily re-match surfaces the compromise against the exact package versions in your applications and triggers an alert, instead of the team learning about it from social media days later.

SecurIT360 runs ChainGarde against its own software: roughly 43,000 components across dozens of internally built tools produced in the last 18 months, most of it work no one would have called "development" two years ago.

What customers gain

A live inventory of every component your software depends on

Daily re-checking against public advisories, continuously as your code changes

Risk scoring that combines severity, active exploitation (KEV), and likelihood (EPSS)

Alerts aligned to the escalation timelines you define

Early warning on supply-chain compromises, matched to your exact package versions