Q: You mentioned implementing shift-left security practices such as SAST and dependency scanning. Where exactly do these security scans execute in the CI/CD pipeline, and at what stage do you make the Go/No-Go decision?
Implementation blueprint for shift-left security scanning in CI/CD pipelines, covering SAST, SCA dependency scanning, container scanning, and automated Go/No-Go quality gates.
Master cloud-native security and container runtime defense: Prepare with KodeKloud's CKS course with live browser-based terminal sandboxes.
🛠️ Production Runbook & Step-by-Step Resolution
Stage 1: Pre-Commit (Developer Workstation - Zero Latency)
Execute local pre-commit hooks using `gitleaks` and linting tools. Catches hardcoded API keys and secrets before code is ever pushed to remote Git repositories.
# .pre-commit-config.yaml
repos:
- repo: https://github.com/gitleaks/gitleaks
rev: v8.18.2
hooks:
- id: gitleaks
Stage 2: Pull Request Gate (SAST & Software Composition Analysis - SCA)
Runs automatically when a developer opens or updates a Pull Request: - **SAST (Static Application Security Testing)**: Tools like SonarQube, Semgrep, or GitHub CodeQL analyze uncompiled source code for injection vulnerabilities (SQLi, XSS) and insecure cryptographic functions. - **SCA (Dependency Scanning)**: Tools like Snyk, Trivy, or OWASP Dependency-Check scan package lockfiles (`pom.xml`, `package-lock.json`) for known Common Vulnerabilities and Exposures (CVEs). - **PR Quality Gate**: PR merge is automatically BLOCKED if high/critical issues are detected.
Stage 3: Post-Build Container Image & IaC Scanning
After the container image is packaged, scan the image filesystem with **Trivy** or **Grype** for OS package vulnerabilities (Debian/Alpine CVEs). Simultaneously, scan Terraform manifests using **Checkov** or **Tfsec** for cloud misconfigurations (e.g. open S3 buckets).
# Trivy Container Scan in CI pipeline
- name: Run Trivy vulnerability scanner
uses: aquasecurity/trivy-action@master
with:
image-ref: 'myregistry.azurecr.io/app:${{ github.sha }}'
format: 'table'
exit-code: '1' # Fails the pipeline
ignore-unfixed: true
severity: 'CRITICAL,HIGH'
The Exact Go/No-Go Gate Decision Matrix
The automated Go/No-Go gate executes **immediately before deploying to staging/production**: - **Hard NO-GO (Build Fails)**: Any vulnerability with CVSS score >= 7.0 (HIGH or CRITICAL) that has a vendor patch available (`ignore-unfixed: true`), or any hardcoded credential detected. - **Conditional GO (Warning & 14-Day SLA Ticket)**: Medium vulnerabilities without active exploits create automated Jira tickets assigned to the repository owner with a 14-day remediation SLA.
- Run secret detection pre-commit with Gitleaks before code leaves the developer machine.
- Execute SAST (SonarQube/Semgrep) and dependency SCA (Snyk/Trivy) in the PR pipeline to block merging.
- Scan packaged container images and Terraform manifests with Trivy and Checkov.
- Enforce automated Go/No-Go gates that fail the build on any High or Critical CVE with an available fix.