⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 1,000+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
← Back to All Security & DevSecOps Interview Questions Scenario 54 of 54 in Security & DevSecOps
Senior DevSecOps / Operations Engineer Security DevSecOps & Shift-Left Security Operations & Support Loop

Q: You mentioned implementing shift-left security practices such as SAST and dependency scanning. Where exactly do these security scans execute in the CI/CD pipeline, and at what stage do you make the Go/No-Go decision?

Implementation blueprint for shift-left security scanning in CI/CD pipelines, covering SAST, SCA dependency scanning, container scanning, and automated Go/No-Go quality gates.

#Security #DevSecOps #SAST #SCA #Trivy #SonarQube #CI/CD #Vulnerability Management
🎙️ Candidate Opening & Architectural Context
"Shift-left security means catching vulnerabilities as early as possible in the software development lifecycle, rather than waiting for penetration tests in staging or production. In modern CI/CD, we execute security scanning across three distinct stages: Pre-Commit, Pull Request (Build), and Artifact Release, with automated Go/No-Go gates blocking insecure builds."
Advertisement
🛡️
⚡ Recommended DevSecOps Track

Master cloud-native security and container runtime defense: Prepare with KodeKloud's CKS course with live browser-based terminal sandboxes.

Prepare with KodeKloud's CKS Course →

🛠️ Production Runbook & Step-by-Step Resolution

1

Stage 1: Pre-Commit (Developer Workstation - Zero Latency)

Execute local pre-commit hooks using `gitleaks` and linting tools. Catches hardcoded API keys and secrets before code is ever pushed to remote Git repositories.

# .pre-commit-config.yaml
repos:
- repo: https://github.com/gitleaks/gitleaks
  rev: v8.18.2
  hooks:
  - id: gitleaks
2

Stage 2: Pull Request Gate (SAST & Software Composition Analysis - SCA)

Runs automatically when a developer opens or updates a Pull Request: - **SAST (Static Application Security Testing)**: Tools like SonarQube, Semgrep, or GitHub CodeQL analyze uncompiled source code for injection vulnerabilities (SQLi, XSS) and insecure cryptographic functions. - **SCA (Dependency Scanning)**: Tools like Snyk, Trivy, or OWASP Dependency-Check scan package lockfiles (`pom.xml`, `package-lock.json`) for known Common Vulnerabilities and Exposures (CVEs). - **PR Quality Gate**: PR merge is automatically BLOCKED if high/critical issues are detected.

Git Push PR→Parallel SAST & SCA→Container Image Scan (Trivy)→Go / No-Go Quality Gate→Deploy to Staging
Advertisement
3

Stage 3: Post-Build Container Image & IaC Scanning

After the container image is packaged, scan the image filesystem with **Trivy** or **Grype** for OS package vulnerabilities (Debian/Alpine CVEs). Simultaneously, scan Terraform manifests using **Checkov** or **Tfsec** for cloud misconfigurations (e.g. open S3 buckets).

# Trivy Container Scan in CI pipeline
- name: Run Trivy vulnerability scanner
  uses: aquasecurity/trivy-action@master
  with:
    image-ref: 'myregistry.azurecr.io/app:${{ github.sha }}'
    format: 'table'
    exit-code: '1' # Fails the pipeline
    ignore-unfixed: true
    severity: 'CRITICAL,HIGH'
4

The Exact Go/No-Go Gate Decision Matrix

The automated Go/No-Go gate executes **immediately before deploying to staging/production**: - **Hard NO-GO (Build Fails)**: Any vulnerability with CVSS score >= 7.0 (HIGH or CRITICAL) that has a vendor patch available (`ignore-unfixed: true`), or any hardcoded credential detected. - **Conditional GO (Warning & 14-Day SLA Ticket)**: Medium vulnerabilities without active exploits create automated Jira tickets assigned to the repository owner with a 14-day remediation SLA.

Pro Tip: DevSecOps Policy: Hard Go/No-Go gates must only block on CRITICAL/HIGH vulnerabilities with available fixes to prevent blocking developers on un-patchable upstream OS CVEs.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Execute SAST and dependency scanning (SCA) on Pull Requests before merging, and container/IaC scanning post-build. Enforce the Go/No-Go gate before deployment: block builds on High/Critical CVEs with available fixes."
⚡ 60-Second Elevator Pitch Talking Points
  • Run secret detection pre-commit with Gitleaks before code leaves the developer machine.
  • Execute SAST (SonarQube/Semgrep) and dependency SCA (Snyk/Trivy) in the PR pipeline to block merging.
  • Scan packaged container images and Terraform manifests with Trivy and Checkov.
  • Enforce automated Go/No-Go gates that fail the build on any High or Critical CVE with an available fix.
Advertisement
Want more Security & DevSecOps scenarios?
Explore our complete collection of scenario-based Security & DevSecOps interview runbooks.
Browse All Security & DevSecOps Questions →