# Build from the bundle root, after loading images/zap-stable-amd64.tar. # Existing pinned ZAP image supplies Bash, Python, Git, Java and ZAP add-ons. FROM localhost/devsecops/zap:20260909 USER root COPY bin/ /opt/devsecops/bin/ COPY scripts/ /opt/devsecops/scripts/ COPY examples/ /opt/devsecops/examples/ COPY cache/grype/ /opt/devsecops/cache/grype/ COPY cache/trivy/ /opt/devsecops/cache/trivy/ COPY containers/ci-security.sh /usr/local/bin/ci-security COPY containers/gitleaks.toml /opt/devsecops/examples/gitleaks.toml COPY containers/test-adapter.sh containers/test-zap.sh /opt/devsecops/tests/ COPY metadata/ /usr/share/licenses/devsecops/ RUN chmod 755 /opt/devsecops/bin/* /opt/devsecops/scripts/*.sh /usr/local/bin/ci-security && \ command -v bash && command -v python3 && command -v git && command -v ssh && \ /opt/devsecops/bin/trivy --version && /opt/devsecops/bin/gitleaks version ENV PATH="/opt/devsecops/bin:/zap:/usr/local/bin:/usr/bin:/bin" \ TRIVY_CACHE_DIR="/opt/devsecops/cache/trivy" \ TRIVY_OFFLINE_SCAN=true TRIVY_SKIP_DB_UPDATE=true TRIVY_SKIP_JAVA_DB_UPDATE=true \ TRIVY_SKIP_CHECK_UPDATE=true TRIVY_SKIP_VERSION_CHECK=true TRIVY_DISABLE_TELEMETRY=true \ GITLEAKS_CONFIG=/opt/devsecops/examples/gitleaks.toml LABEL org.opencontainers.image.title="Offline DevSecOps scanner suite" \ org.opencontainers.image.description="Gitleaks 8.30.1, Trivy 0.74.0, Syft 1.51.1, Grype 0.118.0, ZAP 2.17.0; AMD64" WORKDIR /tmp # Drone supplies its own shell command; no special entrypoint required. # Container root is needed for Drone workspace permissions and writable cache layers. # No privileged mode, host mounts or runtime socket required. ENTRYPOINT [] CMD ["ci-security", "versions"]