[Verse 1]
When you choose a vendor for your pipeline chain
Ask them hard questions, don't let risks remain
Where do they store your secrets and keys
What's their backup plan when systems freeze
Show me your security audit trail
Prove your compliance will never fail
[Chorus]
Who What Where When Why and How
Security questions matter now
Access Control Identity Check
Incident Response protect your tech
Who What Where When Why and How
Build trust before you make that vow
[Verse 2]
CI CD providers need to demonstrate
How they isolate builds and validate
What's your uptime SLA guarantee
Can you handle our velocity
Show us your disaster recovery plan
Prove you're more than just a middle man
[Chorus]
Who What Where When Why and How
Security questions matter now
Access Control Identity Check
Incident Response protect your tech
Who What Where When Why and How
Build trust before you make that vow
[Verse 3]
Registry vendors hold our precious code
What's your encryption method and mode
How do you verify package integrity
Who has admin rights and signing key
Tell us about your scanning tools
Show us how you follow security rules
[Bridge]
SDK and tooling vendors too
Must answer questions through and through
Supply chain attacks are on the rise
Don't let vendors sell you lies
Due diligence is your friend
Verify trust from start to end
[Chorus]
Who What Where When Why and How
Security questions matter now
Access Control Identity Check
Incident Response protect your tech
Who What Where When Why and How
Build trust before you make that vow
[Outro]
Write it down make it official
Every question is beneficial
Vendor questionnaire complete
Makes your supply chain concrete