← docsSecurity

/implementing-devsecops-security-scanning

Implement and operationalize a full DevSecOps security scanning pipeline that combines sec.

Implement and operationalize a full DevSecOps security scanning pipeline that combines secrets detection, SAST, SCA, container scanning, optional DAST, and deterministic security gates in CI/CD.

Category

Security

Execution

10 steps, sequential + gated

Goal

Implement and operationalize a full DevSecOps security scanning pipeline that combines secrets detection, SAST, SCA, container scanning, optional DAST, and deterministic security gates in CI/CD.

Scope

Applies to

  • +Set up DevSecOps scanning in CI/CD
  • +Integrate SAST, SCA, and DAST
  • +Add security gates for pull requests

Does not cover

  • −Trivial changes outside the workflow domain

Triggers

"Set up DevSecOps scanning in CI/CD""Integrate SAST, SCA, and DAST""Add security gates for pull requests""Shift-left security pipeline implementation"

Inputs

  • →Context: environment/system affected
  • →Scope: change boundary
  • →Constraints: policy or hard rules

Invariants

  • 01Security scanning must be deterministic and reproducible from repository state.
  • 02Secrets detection runs before deeper scans and blocks immediately on confirmed secret leaks.
  • 03Merge/deploy gates must be explicit and based on configured severity policy.
  • 04Findings and artifacts must be preserved for auditability (JSON/SARIF/SBOM as configured).
  • 05DAST is optional in PR flow but mandatory for release hardening flows when `stagingUrl` exists.
  • 06This workflow augments, not replaces, manual offensive testing for business logic risk.

Procedure

  1. Step 1Step 1 — **Establish policy and execution boundaries**
  2. Step 2Step 2 — **Implement secrets detection (Gitleaks)**
  3. Step 3Step 3 — **Implement SAST (Semgrep)**
  4. Step 4Step 4 — **Implement SCA and IaC scanning (Trivy)**
  5. Step 5Step 5 — **Implement container image scanning + SBOM**
  6. Step 6Step 6 — **Implement DAST stage (OWASP ZAP) when applicable**
  7. Step 7Step 7 — **Create aggregate security gate**
  8. Step 8Step 8 — **Enforce branch protection and ownership controls**
  9. Step 9Step 9 — **Shift-left developer feedback loop**
  10. Step 10Step 10 — **Verification and closure**

Outputs

  • ▸CI/CD security pipeline configuration in repository workflow files.
  • ▸Policy baseline document with severity thresholds and gate behavior.
  • ▸Scan artifacts (Semgrep, Trivy fs/config/image, optional ZAP outputs, SBOM).
  • ▸Aggregate security gate report with pass/fail rationale.
  • ▸Branch protection checklist and local developer feedback instructions.

Review Gate

  • [ ]Secrets scanning blocks confirmed credential leaks.
  • [ ]SAST, SCA, and container scans run automatically on configured branches.
  • [ ]Gate behavior matches `severityPolicy` and blocks critical/high findings as configured.
  • [ ]Optional DAST is implemented when `stagingUrl` is available or explicitly deferred with rationale.
  • [ ]SBOM is generated and stored for audited builds.
  • [ ]Branch protection requires security checks before merge.