Discussed herein are devices, systems,
machine-readable media, and methods for assessing a
software build for a
vulnerability, generating release recommendations, and implementing a
remedial action to mitigate security risks. A method includes receiving a
Software Bill of Materials (SBOM) that lists one or more libraries used in a
software build, receiving a user-specified administration policy, generating an over overall
provenance bundle from a
metadata of the one or more libraries used in the
software build, implementing a gradient boosted tree
algorithm using both the overall
provenance bundle and the user-specified administration policy to generate a software releasability recommendation, receiving the software releasability recommendation into a Large
Language Model (LLM) to generate a recommendation report detailing one or more software vulnerabilities, and implementing the software releasability recommendation by releasing the
software build or blocking the release of the
software build based on the software releasability recommendation.