/implementing-devsecops-security-scanning
Implement and operationalize a full DevSecOps security scanning pipeline that combines sec.
Implement and operationalize a full DevSecOps security scanning pipeline that combines secrets detection, SAST, SCA, container scanning, optional DAST, and deterministic security gates in CI/CD.
Category
Security
Execution
10 steps, sequential + gated
Goal
Implement and operationalize a full DevSecOps security scanning pipeline that combines secrets detection, SAST, SCA, container scanning, optional DAST, and deterministic security gates in CI/CD.
Scope
Applies to
- +Set up DevSecOps scanning in CI/CD
- +Integrate SAST, SCA, and DAST
- +Add security gates for pull requests
Does not cover
- −Trivial changes outside the workflow domain
Triggers
"Set up DevSecOps scanning in CI/CD""Integrate SAST, SCA, and DAST""Add security gates for pull requests""Shift-left security pipeline implementation"
Inputs
- →Context: environment/system affected
- →Scope: change boundary
- →Constraints: policy or hard rules
Invariants
- 01Security scanning must be deterministic and reproducible from repository state.
- 02Secrets detection runs before deeper scans and blocks immediately on confirmed secret leaks.
- 03Merge/deploy gates must be explicit and based on configured severity policy.
- 04Findings and artifacts must be preserved for auditability (JSON/SARIF/SBOM as configured).
- 05DAST is optional in PR flow but mandatory for release hardening flows when `stagingUrl` exists.
- 06This workflow augments, not replaces, manual offensive testing for business logic risk.
Procedure
- Step 1Step 1 — **Establish policy and execution boundaries**
- Step 2Step 2 — **Implement secrets detection (Gitleaks)**
- Step 3Step 3 — **Implement SAST (Semgrep)**
- Step 4Step 4 — **Implement SCA and IaC scanning (Trivy)**
- Step 5Step 5 — **Implement container image scanning + SBOM**
- Step 6Step 6 — **Implement DAST stage (OWASP ZAP) when applicable**
- Step 7Step 7 — **Create aggregate security gate**
- Step 8Step 8 — **Enforce branch protection and ownership controls**
- Step 9Step 9 — **Shift-left developer feedback loop**
- Step 10Step 10 — **Verification and closure**
Outputs
- ▸CI/CD security pipeline configuration in repository workflow files.
- ▸Policy baseline document with severity thresholds and gate behavior.
- ▸Scan artifacts (Semgrep, Trivy fs/config/image, optional ZAP outputs, SBOM).
- ▸Aggregate security gate report with pass/fail rationale.
- ▸Branch protection checklist and local developer feedback instructions.
Review Gate
- [ ]Secrets scanning blocks confirmed credential leaks.
- [ ]SAST, SCA, and container scans run automatically on configured branches.
- [ ]Gate behavior matches `severityPolicy` and blocks critical/high findings as configured.
- [ ]Optional DAST is implemented when `stagingUrl` is available or explicitly deferred with rationale.
- [ ]SBOM is generated and stored for audited builds.
- [ ]Branch protection requires security checks before merge.