Build-Time vs Repo-Time SBOM Generation

Software Supply Chain Security · 3:03

Listen on 93

Lyrics

[Verse 1]
When your code compiles and builds each day
There's a choice to make along the way
Generate your SBOM right here and now
Or scan the repo when time allows
Build-time captures what actually ships
Every dependency that your code grips
Real components in the final state
Not just what the manifest might translate

[Chorus]
Build or repo, when do you know
What's inside your software flow
Build-time's real but repo's fast
Which approach will help you last
SBOM generation, two roads to take
Choose the timing for security's sake
Build or repo, the choice is yours
For supply chain's open doors

[Verse 2]
Repository scanning reads the files
Parses manifests across the miles
Package dot json, requirements text
Gemfiles show what might come next
But declared dependencies aren't the truth
Some get pruned, some substituted proof
What you see in source control today
Might not match what's in production's way

[Chorus]
Build or repo, when do you know
What's inside your software flow
Build-time's real but repo's fast
Which approach will help you last
SBOM generation, two roads to take
Choose the timing for security's sake
Build or repo, the choice is yours
For supply chain's open doors

[Bridge]
Build-time's accurate but takes more time
Slows the pipeline, could break your rhyme
Repo's faster, gives you speed
But might not catch what you really need
Hybrid approaches find the way
Use both methods, night and day
Critical apps need build-time truth
Development can use repo proof

[Verse 3]
Consider your threat model and your goals
Are you tracking every bit and byte that rolls
Or do you need a quick inventory check
To spot the risks before they wreck
Compliance frameworks have their say
Some require build-time's accurate way
Others accept the repo scan
Choose the method that fits your plan

[Chorus]
Build or repo, when do you know
What's inside your software flow
Build-time's real but repo's fast
Which approach will help you last
SBOM generation, two roads to take
Choose the timing for security's sake
Build or repo, the choice is yours
For supply chain's open doors

[Outro]
Know your components, know your risk
Build or repo, don't dismiss
The power of the SBOM's light
To keep your software supply chain right

← CycloneDX Standard: Security-Focused SBOM Format | Container SBOM Generation: Images and Layers →