Skip to content
AITroveRead. Build. Understand.
Make this comfortable

SBOM scope: distinguish build inputs from shipped components

Last updated: 5 Oct 20266 min read
tutorial
AdvancedBy AITrove Editorial

A dependency lockfile, source-tree scan, and final-image scan answer different questions. The lockfile can include development packages that never ship; a final container can contain operating-system packages, copied binaries, and layers absent from the language lockfile. A useful SBOM states its subject, generation point, components, dependency relationships where known, and gaps. A package list with no relation to a deployable digest cannot settle which production release contains a vulnerable component.

Operational decision

A payment-reconciliation worker is built in two stages. Generate one dependency view from the locked application build and another from the final runtime image. Record the image digest, architecture, generator version, scan mode, and time for each view. Compare the two inventories: flag runtime packages missing from the lockfile view, build-only compilers that should not appear in the final image, and copied binaries whose package origin the scanner cannot identify. Run the process in a disposable container and inspect loaded modules to test whether the scanner missed a statically linked component. Keep unknown entries as unknown; inventing a package version to make coverage appear complete makes later advisory matching worse. For a multi-architecture release, inspect each platform manifest because its base packages may differ. Store the accepted inventories with the release digest and regenerate them when the image is rebuilt, even if application source did not change. Do not publish internal repository credentials or private download paths through SBOM metadata. The inventory is operational evidence, not a guarantee that no other code is present.

Output
Payment worker inventory contract
Subject: final image digest and platform
Sources: lockfile view plus final-image view
Generator: version and scan mode recorded
Relationships: direct and transitive edges where known
Unknowns: copied binary and unidentified packages reported
Acceptance: runtime image matches recorded subject digest

Cost and verification

Scanning B bytes and P package records costs at least O(B + P) work for a full image pass; graph storage grows with components and dependency edges. More complete scans add pipeline time and artifact storage, but missing runtime packages make incident triage slower. Measure runtime-component coverage, unidentified bytes, stale inventories, and differences between platform variants. A smaller SBOM is not necessarily better if it silently omits the shipped base layer.

Common Mistakes

  • Do not present a lockfile inventory as the entire final image.
  • Do not attach one platform's SBOM to every architecture in an image index.
  • Do not turn unknown package identities into guessed versions.

Connected lessons

Practice and check

devops
supply-chain
Storage details