Security scanning only works when developers trust it. If every PR waits twenty minutes for noisy findings, teams bypass the gate—or stop opening PRs altogether.
Start with a short, high-signal set: secrets detection on every commit, dependency scanning with fix PRs, SAST on changed paths, and container image scans before promotion. Fail the build only on severity thresholds the security team actually owns.
Store SBOMs with artifacts, sign images, and keep credentials out of runners with short-lived OIDC federation. Progressive delivery (canary or blue/green) then becomes the last safety net—not the first line of defense.
Done well, secure CI/CD reduces incident load without turning delivery into a ticket queue.
Store SBOMs with artifacts and sign images so admission policies can verify what actually ships.
Separate build identity from runtime identity. A compromised CI role should not equal permanent production admin.
Track mean time to remediate critical findings as a platform KPI alongside deployment frequency.
Key takeaways
- Fail builds on severity the security team owns—not every scanner finding.
- Prefer fast, high-signal checks on changed paths before slow full-repo scans.
- Use short-lived OIDC credentials; never store long-lived cloud keys in runners.
FAQ
Which gates should be mandatory on every PR?
Secrets detection, dependency vulnerability checks with clear fix paths, and SAST on changed code. Heavier container or IaC scans can run on merge or nightly if PR latency matters.
How do we stop teams bypassing gates?
Keep signal high, publish ownership of false positives, and measure time-to-green. Noisy gates create shadow pipelines; trusted gates get adopted.