diff --git a/.github/actions/notify_quartz/action.yml b/.github/actions/notify_quartz/action.yml index f3000a5686..14c6db641d 100644 --- a/.github/actions/notify_quartz/action.yml +++ b/.github/actions/notify_quartz/action.yml @@ -96,6 +96,7 @@ runs: client-id: ${{ inputs.gh_app_client_id }} private-key: ${{ inputs.gh_app_private_key }} repositories: ${{ inputs.quartz_repo }} + permission-actions: write - name: Notify Quartz if: steps.app-token.outputs.token != '' diff --git a/.github/workflows/receive_therock_data.yml b/.github/workflows/receive_therock_data.yml index 88bc550728..52ddf8babe 100644 --- a/.github/workflows/receive_therock_data.yml +++ b/.github/workflows/receive_therock_data.yml @@ -40,6 +40,7 @@ jobs: client-id: ${{ secrets.GH_APP_QUARTZ_SYNC_CID }} private-key: ${{ secrets.GH_APP_QUARTZ_SYNC_PRIVATE_KEY }} repositories: Quartz + permission-contents: write - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: diff --git a/.github/workflows/security_scan_pr.yml b/.github/workflows/security_scan_pr.yml new file mode 100644 index 0000000000..62061b21c9 --- /dev/null +++ b/.github/workflows/security_scan_pr.yml @@ -0,0 +1,25 @@ +# Copyright Advanced Micro Devices, Inc. +# SPDX-License-Identifier: MIT +# +# Pre-commit security gate: fast, PR-side security scanners that run on +# every pull request. The security counterpart to `pre-commit.yml`. The +# set of scanners lives in `security-baseline.yml`, so scanners coming +# online are picked up here without touching this file. + +name: Security scan (PR) + +on: + pull_request: + +permissions: + contents: read + +concurrency: + group: ${{ github.workflow }}-${{ github.event.pull_request.number }} + cancel-in-progress: true + +jobs: + security: + uses: ROCm/rocm-security-gh/.github/workflows/security-baseline.yml@31ec6f8dd59194dc8a94436865342fd00dea73fd # v1.0.0 + with: + report_formats: human diff --git a/.github/workflows/security_scan_weekly.yml b/.github/workflows/security_scan_weekly.yml new file mode 100644 index 0000000000..fbdd87c247 --- /dev/null +++ b/.github/workflows/security_scan_weekly.yml @@ -0,0 +1,29 @@ +# Copyright Advanced Micro Devices, Inc. +# SPDX-License-Identifier: MIT +# +# Weekly security scan: runs on a fixed cadence and pushes SARIF findings +# to the repository's code-scanning Security tab. Complements +# `pr-security-scan.yml`, which scans only what changed in a PR and +# uploads reviewer-readable artifacts for in-review browsing. + +name: Security scan (Weekly) + +on: + # Run every Saturday at 10:00 UTC. + schedule: + - cron: "0 10 * * 6" + workflow_dispatch: + +permissions: + contents: read + +jobs: + security: + # Only the job that uploads SARIF gets write access to code scanning. + permissions: + contents: read + security-events: write + uses: ROCm/rocm-security-gh/.github/workflows/security-baseline.yml@31ec6f8dd59194dc8a94436865342fd00dea73fd # v1.0.0 + with: + scan_mode: all + report_formats: sarif diff --git a/.github/workflows/sync_develop_to_main.yml b/.github/workflows/sync_develop_to_main.yml index 800d78953e..47d041a1f0 100644 --- a/.github/workflows/sync_develop_to_main.yml +++ b/.github/workflows/sync_develop_to_main.yml @@ -27,6 +27,7 @@ jobs: client-id: ${{ secrets.GH_APP_QUARTZ_SYNC_CID }} private-key: ${{ secrets.GH_APP_QUARTZ_SYNC_PRIVATE_KEY }} repositories: Quartz + permission-contents: write - name: Checkout main uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 8801a0deda..c410045f7b 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -50,3 +50,47 @@ Notes: is titled `Merge develop () into main` and records the synced commit's hash, subject, author, and date in its body, so it is easy to tell the merge commit apart from the original `develop` commit. + +## Security scanners + +Separately from the correctness checks covered by TheRock's `CONTRIBUTING.md`, +this repository scans for secrets, unsafe Python, and workflow +vulnerabilities. These run in CI via +[`security_scan_pr.yml`](.github/workflows/security_scan_pr.yml), which calls +the shared [`ROCm/rocm-security-gh`](https://github.com/ROCm/rocm-security-gh) +reusable workflow. See +[the automated security scanning section in `SECURITY.md`](SECURITY.md#automated-security-scanning) +for how the PR-time and weekly workflows fit together. + +Each scanner is runnable locally against the same configuration CI uses, +which is faster than pushing a commit to see what CI says. The +configurations live at the repo root: + +```bash +# Secrets, working tree only. Recommended much faster, and usually what you want locally. +gitleaks detect --source . --config gitleaks.toml --redact --no-banner --no-git + +# Secrets, over the full git history. Takes longer than the working tree one above. +gitleaks detect --source . --config gitleaks.toml --redact --verbose --no-banner + +# Unsafe patterns in Python (pip install bandit). +bandit --configfile bandit.yml --severity-level low --recursive . + +# GitHub Actions workflow vulnerabilities (pip install zizmor). +zizmor --persona regular --config zizmor.yml . + +# Dependency vulnerabilities and misconfigurations (see trivy docs). +trivy fs --config trivy.yml --severity LOW,MEDIUM,HIGH,CRITICAL --scanners misconfig,vuln . +``` + +> [!NOTE] +> These commands report every severity, while CI only fails on `HIGH` (and +> `CRITICAL` for trivy). Expect more output locally than a red CI check implies. +> +> The commands also scan the whole repository, while pull request runs default +> to scanning only what the pull request changed. A full-history `gitleaks` run +> in particular reports pre-existing findings that the pull request check does +> not. + +CodeQL is not in the list above: it runs in CI only, against the org-wide +default configuration (Quartz does not override it locally). diff --git a/SECURITY.md b/SECURITY.md index cf466d848a..e8eebdf753 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -13,3 +13,45 @@ We aim to acknowledge reports within 1 business day. ## Scope This policy covers code and configuration in this repository. For vulnerabilities in third-party dependencies, report upstream. For AMD product issues unrelated to this repo, use the [AMD Product Security portal](https://www.amd.com/en/resources/product-security.html). + +## Automated security scanning + +Alongside the reporting path above, this repository is scanned automatically. +The scanners are not implemented here: Quartz calls the shared +[`ROCm/rocm-security-gh`](https://github.com/ROCm/rocm-security-gh) +`security-baseline.yml` reusable workflow, so the scanner versions and +behavior are maintained centrally for ROCm, and this repository supplies only +its own configuration (the `*.yml` / `*.toml` files at the repo root). + +| Scanner | Looks for | Configuration | +| ------------------------------------------------ | -------------------------------------------------------- | ------------------------------------ | +| [gitleaks](https://github.com/gitleaks/gitleaks) | Secrets and credentials in tracked files and git history | [`gitleaks.toml`](gitleaks.toml) | +| [bandit](https://bandit.readthedocs.io/) | Unsafe patterns in our Python scripts | [`bandit.yml`](bandit.yml) | +| [zizmor](https://docs.zizmor.sh/) | GitHub Actions workflow vulnerabilities | [`zizmor.yml`](zizmor.yml) | +| [trivy](https://trivy.dev/) | Dependency vulnerabilities and misconfigurations | [`trivy.yml`](trivy.yml) | +| [CodeQL](https://codeql.github.com/) | Semantic code analysis of our Python | org-wide default (no local override) | + +Two workflows run them, and where a finding shows up depends on which one +produced it: + +- [`security_scan_pr.yml`](.github/workflows/security_scan_pr.yml) runs on + every pull request, scoped to what that pull request changed. It reports in + the job summary and a build artifact, and deliberately does not upload to + the Security tab, so pull requests from forks behave the same as those from + branches in this repository. +- [`security_scan_weekly.yml`](.github/workflows/security_scan_weekly.yml) + runs on a schedule across the whole repository and uploads SARIF to this + repository's Security tab, which is the authoritative view of the current + state. Quartz is a monorepo-adjacent, low-churn repository, so a weekly + cadence (rather than on every push to `develop`/`main`) is enough to keep + the Security tab current without adding a scan to every merge. + +> [!IMPORTANT] +> A finding from these scanners is not a vulnerability report. If a scanner +> finding turns out to be an exploitable vulnerability in shipped ROCm +> software, report it through the AMD Product Security portal above rather +> than in a public issue or pull request. + +Contributors can run every scanner locally against the same configuration CI +uses; see +[the security scanners section in `CONTRIBUTING.md`](CONTRIBUTING.md#security-scanners). diff --git a/bandit.yml b/bandit.yml new file mode 100644 index 0000000000..74c28e436b --- /dev/null +++ b/bandit.yml @@ -0,0 +1,15 @@ +# Copyright Advanced Micro Devices, Inc. +# SPDX-License-Identifier: MIT +# +# bandit configuration for Quartz, picked up by the rocm-security-gh +# reusable scanner (.github/workflows/security_scan_pr.yml and +# security_scan_weekly.yml) in place of its own org-wide default. +# Reference: https://bandit.readthedocs.io/en/latest/config.html + +exclude_dirs: + - .git + - .venv + - venv + - release-nightly + - prerelease + - nightly diff --git a/gitleaks.toml b/gitleaks.toml new file mode 100644 index 0000000000..5235bbe01f --- /dev/null +++ b/gitleaks.toml @@ -0,0 +1,14 @@ +# Copyright Advanced Micro Devices, Inc. +# SPDX-License-Identifier: MIT +# +# gitleaks configuration for Quartz, picked up by the rocm-security-gh +# reusable scanner (.github/workflows/security_scan_pr.yml and +# security_scan_weekly.yml) in place of its own org-wide default. +# Reference: https://github.com/gitleaks/gitleaks/blob/master/config/gitleaks.toml + +title = "Quartz gitleaks config" + +[extend] +# Inherit gitleaks' built-in ruleset (rotations, AWS, GCP, Slack, ...) +# rather than rolling our own detections. +useDefault = true diff --git a/scripts/receive_therock/tests/therock_workflow_registry_test.py b/scripts/receive_therock/tests/therock_workflow_registry_test.py index 2139b7beb1..0ef0d2ac10 100644 --- a/scripts/receive_therock/tests/therock_workflow_registry_test.py +++ b/scripts/receive_therock/tests/therock_workflow_registry_test.py @@ -89,6 +89,8 @@ "bender.yml", "sync_develop_to_main.yml", "pre_commit.yml", + "security_scan_pr.yml", + "security_scan_weekly.yml", } ) diff --git a/trivy.yml b/trivy.yml new file mode 100644 index 0000000000..77ed054964 --- /dev/null +++ b/trivy.yml @@ -0,0 +1,15 @@ +# Copyright Advanced Micro Devices, Inc. +# SPDX-License-Identifier: MIT +# +# trivy configuration for Quartz, picked up by the rocm-security-gh +# reusable scanner (.github/workflows/security_scan_pr.yml and +# security_scan_weekly.yml) in place of its own org-wide default. +# Reference: https://trivy.dev/latest/docs/references/configuration/config-file/ + +scan: + skip-dirs: + - .git + - .venv + - venv + - release-nightly + - prereleases diff --git a/zizmor.yml b/zizmor.yml new file mode 100644 index 0000000000..d3ee605482 --- /dev/null +++ b/zizmor.yml @@ -0,0 +1,9 @@ +# Copyright Advanced Micro Devices, Inc. +# SPDX-License-Identifier: MIT +# +# zizmor configuration for Quartz, picked up by the rocm-security-gh +# reusable scanner (.github/workflows/security_scan_pr.yml and +# security_scan_weekly.yml) in place of its own org-wide default. +# Reference: https://docs.zizmor.sh/configuration/ + +rules: {}