# Merge these steps into your existing build flow; this example requires a Drone EXEC runner. # Keep Docker pipelines on Docker runners; the guide explains that alternative. kind: pipeline type: exec name: security platform: os: linux arch: amd64 steps: - name: source-security commands: - export TRIVY_CACHE_DIR="$DRONE_WORKSPACE/../security-cache-$DRONE_BUILD_NUMBER" - mkdir -p "$TRIVY_CACHE_DIR" - cp -a /opt/devsecops/cache/trivy/. "$TRIVY_CACHE_DIR/" - /opt/devsecops/scripts/scan-source.sh "$DRONE_WORKSPACE" "$DRONE_WORKSPACE/../security-reports-$DRONE_BUILD_NUMBER" - name: supply-chain commands: - export GRYPE_DB_CACHE_DIR="$DRONE_WORKSPACE/../grype-cache-$DRONE_BUILD_NUMBER" - mkdir -p "$GRYPE_DB_CACHE_DIR" - cp -a /opt/devsecops/cache/grype/. "$GRYPE_DB_CACHE_DIR/" - /opt/devsecops/scripts/scan-supply-chain.sh dir "$DRONE_WORKSPACE" "$DRONE_WORKSPACE/../supply-chain-$DRONE_BUILD_NUMBER" # Existing build -> scan-image.sh -> SonarQube gate -> staging/openQA/ZAP -> promotion. # Use an isolated runner dedicated to trusted repositories. Restrict promotion credentials to protected release jobs.