# Pinned versions for the offline Drone + SCA bundle. Change only after review: # bump the values here, re-run scripts/00-download.sh and # scripts/05-build-scanner-image.sh on the connected builder, then re-run # scripts/30-verify-offline.sh. # # Digests were resolved on 2026-09-11. 00-download.sh refuses to continue if an # upstream tag has moved away from the digest recorded here. # --- Drone server (Community/Enterprise image, Gitea provider) --------------- DRONE_VERSION=2.24.0 DRONE_IMAGE_REPO=docker.io/drone/drone DRONE_IMAGE_INDEX_DIGEST=sha256:b6489b615daf4eb436443c8e39dd3cf8ac8c8c9ce216a7a40a27118719777845 DRONE_IMAGE_AMD64_DIGEST=sha256:0db82b6215a50a841416586048e451e226f6cd8e2106dbfe7fe5c736fb7ff562 DRONE_IMAGE_LOCAL=docker.io/drone/drone:2.24.0 # --- Drone Docker runner ---------------------------------------------------- RUNNER_VERSION=1.8.5 RUNNER_IMAGE_REPO=docker.io/drone/drone-runner-docker RUNNER_IMAGE_INDEX_DIGEST=sha256:ead7d7807f878c89038dcdf0383336ffe50a1724b9cb6ff963b0e97279d078e2 RUNNER_IMAGE_AMD64_DIGEST=sha256:77097e06172c5872bde9a44144a0701ded6ef7597aba9bf531aafe4e26e33b91 RUNNER_IMAGE_LOCAL=docker.io/drone/drone-runner-docker:1.8.5 # --- Clone image the runner injects into every pipeline --------------------- # Upstream only publishes "latest" for current builds (2023-01-04). The runner # defaults to drone/git:latest; we pin its digest and set # DRONE_RUNNER_CLONE_IMAGE explicitly so nothing ever tries to pull it. GIT_IMAGE_REPO=docker.io/drone/git GIT_IMAGE_INDEX_DIGEST=sha256:82182ff192f26236456951e13e8641eaed40f001f1461c1cd3f45140de0e37ed GIT_IMAGE_AMD64_DIGEST=sha256:c0f7ca05785e2b02a87261afb775c49bc464e45a1465bc7c197c8e697eabced7 GIT_IMAGE_LOCAL=docker.io/drone/git:latest # --- Base image for the scanner image (Red Hat UBI 9 minimal) --------------- UBI_IMAGE_REPO=registry.access.redhat.com/ubi9/ubi-minimal UBI_IMAGE_INDEX_DIGEST=sha256:d235f607e1d6d833f031db107dc42206e4dd4d5aa9142c43d3771fb7f9bea76a UBI_IMAGE_AMD64_DIGEST=sha256:b061cda54b60dbe0c4746369a0af84b914af226e19cde4612b62e2e12e4371e6 UBI_IMAGE_LOCAL=registry.access.redhat.com/ubi9/ubi-minimal:9.8 # RPMs added to the base (downloaded from the UBI repos, GPG-checked at build). UBI_EXTRA_RPMS="jq oniguruma tar gzip" # --- Scanners (release tarballs, SHA-256 from the upstream checksums files) -- SYFT_VERSION=1.51.1 SYFT_SHA256=8fcb33017a0dc1058298c923c436d19dfa68ae93968e0b423248542e3afb9fc3 GRYPE_VERSION=0.118.0 GRYPE_SHA256=1d444c5e7360471815f7158f71935fcecc68a3c417d85c7344f770854300bba2 TRIVY_VERSION=0.74.0 TRIVY_SHA256=2ae6fe3ee734b7fdf11335663e18c75ea12dccc76062f09f164a3b0f8be4371a # --- Drone CLI (admin tasks: secrets, repo settings, cron) ------------------ DRONE_CLI_VERSION=1.9.0 DRONE_CLI_SHA256=9a9b8a254829edbce4fd3a895d6338fc59164a5a6b78a3d945120c4ff6963f3b # --- Vulnerability data ------------------------------------------------------- # Grype: schema v6, listing at https://grype.anchore.io/databases/v6/latest.json GRYPE_DB_SCHEMA=v6 # Trivy: OCI artifacts pulled by trivy itself (digest-verified on pull). TRIVY_DB_REPOSITORY=mirror.gcr.io/aquasec/trivy-db:2 TRIVY_JAVA_DB_REPOSITORY=mirror.gcr.io/aquasec/trivy-java-db:1 TRIVY_CHECKS_BUNDLE_REPOSITORY=mirror.gcr.io/aquasec/trivy-checks:2 # --- Scanner image produced by 05-build-scanner-image.sh -------------------- # The tag is the UTC date of the vulnerability data inside it, e.g. 20260911. SCANNER_IMAGE_REPO=localhost/devsecops/drone-scanners # Maximum vulnerability-data age accepted by `drone-scan db-check` (days). MAX_DB_AGE_DAYS=7