# Offline SCA scanner image for Drone: Syft + Grype + Trivy on Red Hat UBI 9 # minimal, with all vulnerability data baked in. Built by # scripts/05-build-scanner-image.sh from a staged context — no network access # is needed or allowed during the build (podman build --network=none). # # The image tag is the date of the vulnerability data. Rebuild it on your # refresh cadence; drone-scan db-check fails builds once the data is older # than MAX_DB_AGE_DAYS. ARG BASE_IMAGE=registry.access.redhat.com/ubi9/ubi-minimal:9.8 FROM ${BASE_IMAGE} ARG SYFT_VERSION ARG GRYPE_VERSION ARG TRIVY_VERSION ARG DATA_DATE ARG GRYPE_DB_BUILT ARG TRIVY_DB_UPDATED ARG MAX_DB_AGE_DAYS=7 LABEL org.opencontainers.image.title="devsecops drone-scanners" \ org.opencontainers.image.description="Offline Syft/Grype/Trivy scanners for Drone pipelines" \ org.opencontainers.image.version="${DATA_DATE}" \ devsecops.syft.version="${SYFT_VERSION}" \ devsecops.grype.version="${GRYPE_VERSION}" \ devsecops.trivy.version="${TRIVY_VERSION}" \ devsecops.grype.db.built="${GRYPE_DB_BUILT}" \ devsecops.trivy.db.updated="${TRIVY_DB_UPDATED}" # jq/tar/gzip from the UBI repos; signatures verified against the Red Hat key # shipped in the base image before anything is installed. COPY rpms/ /tmp/rpms/ RUN rpm --import /etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release \ && rpm -K /tmp/rpms/*.rpm \ && rpm -Uvh /tmp/rpms/*.rpm \ && rm -rf /tmp/rpms # Vulnerability data first (largest, changes on every refresh), one layer each. COPY db/grype/ /opt/scanners/grype/ COPY db/trivy/db/ /opt/scanners/trivy/db/ COPY db/trivy/java-db/ /opt/scanners/trivy/java-db/ COPY db/trivy/policy/ /opt/scanners/trivy/policy/ COPY bin/ /usr/local/bin/ COPY etc/ /etc/devsecops/ # Offline behaviour is also enforced by drone-scan's explicit flags; these # cover direct use of the scanner binaries inside pipeline steps. ENV SYFT_CHECK_FOR_APP_UPDATE=false \ GRYPE_CHECK_FOR_APP_UPDATE=false \ GRYPE_DB_CACHE_DIR=/opt/scanners/grype \ GRYPE_DB_AUTO_UPDATE=false \ GRYPE_DB_REQUIRE_UPDATE_CHECK=false \ GRYPE_DB_VALIDATE_AGE=true \ GRYPE_DB_MAX_ALLOWED_BUILT_AGE=168h \ TRIVY_CACHE_DIR=/opt/scanners/trivy \ TRIVY_SKIP_DB_UPDATE=true \ TRIVY_SKIP_JAVA_DB_UPDATE=true \ TRIVY_SKIP_CHECK_UPDATE=true \ TRIVY_OFFLINE_SCAN=true \ TRIVY_SKIP_VERSION_CHECK=true \ TRIVY_DISABLE_TELEMETRY=true \ TRIVY_NO_PROGRESS=true \ MAX_DB_AGE_DAYS=${MAX_DB_AGE_DAYS} \ SCANNER_DATA_DATE=${DATA_DATE} RUN chmod 0755 /usr/local/bin/syft /usr/local/bin/grype /usr/local/bin/trivy /usr/local/bin/drone-scan \ && syft version >/dev/null && grype version >/dev/null && trivy --version >/dev/null WORKDIR /tmp CMD ["drone-scan", "help"]