<?xml version="1.0" encoding="UTF-8"?><oembed><type>video</type><version>1.0</version><html>&lt;iframe src=&quot;https://www.loom.com/embed/5afe4be86c164796bbec29df1a6ff330&quot; frameborder=&quot;0&quot; width=&quot;1920&quot; height=&quot;1440&quot; webkitallowfullscreen mozallowfullscreen allowfullscreen&gt;&lt;/iframe&gt;</html><height>1440</height><width>1920</width><provider_name>Loom</provider_name><provider_url>https://www.loom.com</provider_url><thumbnail_height>1440</thumbnail_height><thumbnail_width>1920</thumbnail_width><thumbnail_url>https://cdn.loom.com/sessions/thumbnails/5afe4be86c164796bbec29df1a6ff330-3df7cb9c9e3fc6f3.gif</thumbnail_url><duration>147.24266699999998</duration><title>ShieldGraph Supply Chain Blast Radius Analyzer</title><description>Add ShieldGraph: 3D software supply chain vulnerability and blast radius analyzer

 

### Overview

- Introduces **ShieldGraph**, a live-deployed software supply chain vulnerability and blast radius analyzer backed by **MongoDB Cloud**.
- Adds an interactive **3D WebGL topology view** of the microservice infrastructure, with support for: 
  - zooming and rotating the graph
  - switching between **3D** and **2D canvas** views
  - inspecting microservices, packages, and CVE-linked nodes
- Implements a **Vulnerabilities** workflow that lets users: 
  - review top CVEs
  - analyze **blast radius** for a selected vulnerability
  - simulate an **upstream patch** and observe topology impact
- Includes an **Entity Inspector** for node-level details such as CVSS score and exposure context.
- Adds **risk/exposure matrices** to highlight critical services such as gateways, processing APIs, and billing engines.
- Uses the **official Neo4j driver** with parameterized queries to support graph traversal and avoid recursive CTE/join bottlenecks common in relational databases.
- Deployed live on **Vercel**.

### Assumptions

- The transcript refers to the backing database as &quot;CongoDB Cloud&quot;; this is assumed to mean **MongoDB Cloud**.
- The red nodes in the 3D graph are assumed to represent **CVE/vulnerability nodes** based on the narration.
- The PR includes both UI and backend graph-query changes needed to support topology rendering, blast-radius analysis, and patch simulation.
- The live deployment on Vercel is part of the submitted deliverable and not a separate environment-specific change.

### Testing Strategy

- Verified the 3D topology renders correctly in the browser and supports zoom/rotate interactions.
- Confirmed the app can switch between **3D WebGL** and **2D canvas** views without losing graph context.
- Tested vulnerability selection and **blast radius analysis** using one of the top CVEs.
- Exercised the **Simulate Upstream Patch** flow and confirmed the topology updates as expected.
- Checked the **Entity Inspector** displays the expected CVSS score and node metadata.
- Validated graph queries are executed through the **official Neo4j driver** with parameterized inputs.
- Confirmed the application is deployed and accessible on **Vercel**.

### Link to Loom

</description></oembed>