[Verse 1] When your code compiles and builds each day There's a choice to make along the way Generate your SBOM right here and now Or scan the repo when time allows Build-time captures what actually ships Every dependency that your code grips Real components in the final state Not just what the manifest might translate [Chorus] Build or repo, when do you know What's inside your software flow Build-time's real but repo's fast Which approach will help you last SBOM generation, two roads to take Choose the timing for security's sake Build or repo, the choice is yours For supply chain's open doors [Verse 2] Repository scanning reads the files Parses manifests across the miles Package dot json, requirements text Gemfiles show what might come next But declared dependencies aren't the truth Some get pruned, some substituted proof What you see in source control today Might not match what's in production's way [Chorus] Build or repo, when do you know What's inside your software flow Build-time's real but repo's fast Which approach will help you last SBOM generation, two roads to take Choose the timing for security's sake Build or repo, the choice is yours For supply chain's open doors [Bridge] Build-time's accurate but takes more time Slows the pipeline, could break your rhyme Repo's faster, gives you speed But might not catch what you really need Hybrid approaches find the way Use both methods, night and day Critical apps need build-time truth Development can use repo proof [Verse 3] Consider your threat model and your goals Are you tracking every bit and byte that rolls Or do you need a quick inventory check To spot the risks before they wreck Compliance frameworks have their say Some require build-time's accurate way Others accept the repo scan Choose the method that fits your plan [Chorus] Build or repo, when do you know What's inside your software flow Build-time's real but repo's fast Which approach will help you last SBOM generation, two roads to take Choose the timing for security's sake Build or repo, the choice is yours For supply chain's open doors [Outro] Know your components, know your risk Build or repo, don't dismiss The power of the SBOM's light To keep your software supply chain right
← CycloneDX Standard: Security-Focused SBOM Format | Container SBOM Generation: Images and Layers →