Open Source Software Supply Chain: Automated Risk Assessment