{"type":"video","version":"1.0","html":"<iframe src=\"https://www.loom.com/embed/5afe4be86c164796bbec29df1a6ff330\" frameborder=\"0\" width=\"1920\" height=\"1440\" webkitallowfullscreen mozallowfullscreen allowfullscreen></iframe>","height":1440,"width":1920,"provider_name":"Loom","provider_url":"https://www.loom.com","thumbnail_height":1440,"thumbnail_width":1920,"thumbnail_url":"https://cdn.loom.com/sessions/thumbnails/5afe4be86c164796bbec29df1a6ff330-3df7cb9c9e3fc6f3.gif","duration":147.24266699999998,"title":"ShieldGraph Supply Chain Blast Radius Analyzer","description":"Add ShieldGraph: 3D software supply chain vulnerability and blast radius analyzer\n\n \n\n### Overview\n\n- Introduces **ShieldGraph**, a live-deployed software supply chain vulnerability and blast radius analyzer backed by **MongoDB Cloud**.\n- Adds an interactive **3D WebGL topology view** of the microservice infrastructure, with support for: \n  - zooming and rotating the graph\n  - switching between **3D** and **2D canvas** views\n  - inspecting microservices, packages, and CVE-linked nodes\n- Implements a **Vulnerabilities** workflow that lets users: \n  - review top CVEs\n  - analyze **blast radius** for a selected vulnerability\n  - simulate an **upstream patch** and observe topology impact\n- Includes an **Entity Inspector** for node-level details such as CVSS score and exposure context.\n- Adds **risk/exposure matrices** to highlight critical services such as gateways, processing APIs, and billing engines.\n- Uses the **official Neo4j driver** with parameterized queries to support graph traversal and avoid recursive CTE/join bottlenecks common in relational databases.\n- Deployed live on **Vercel**.\n\n### Assumptions\n\n- The transcript refers to the backing database as \"CongoDB Cloud\"; this is assumed to mean **MongoDB Cloud**.\n- The red nodes in the 3D graph are assumed to represent **CVE/vulnerability nodes** based on the narration.\n- The PR includes both UI and backend graph-query changes needed to support topology rendering, blast-radius analysis, and patch simulation.\n- The live deployment on Vercel is part of the submitted deliverable and not a separate environment-specific change.\n\n### Testing Strategy\n\n- Verified the 3D topology renders correctly in the browser and supports zoom/rotate interactions.\n- Confirmed the app can switch between **3D WebGL** and **2D canvas** views without losing graph context.\n- Tested vulnerability selection and **blast radius analysis** using one of the top CVEs.\n- Exercised the **Simulate Upstream Patch** flow and confirmed the topology updates as expected.\n- Checked the **Entity Inspector** displays the expected CVSS score and node metadata.\n- Validated graph queries are executed through the **official Neo4j driver** with parameterized inputs.\n- Confirmed the application is deployed and accessible on **Vercel**.\n\n### Link to Loom\n\n"}