From b9201eebeb0f33aa5d63a45d8fee2952ada86758 Mon Sep 17 00:00:00 2001 From: Ciprian Goea Date: Mon, 31 Aug 2026 19:22:02 +0300 Subject: [PATCH 01/13] enable security scanners from rocm-security --- .github/workflows/security_scan_pr.yml | 23 +++++++++++++++++ .github/workflows/security_scan_weekly.yml | 30 ++++++++++++++++++++++ 2 files changed, 53 insertions(+) create mode 100644 .github/workflows/security_scan_pr.yml create mode 100644 .github/workflows/security_scan_weekly.yml diff --git a/.github/workflows/security_scan_pr.yml b/.github/workflows/security_scan_pr.yml new file mode 100644 index 0000000000..d976ed68fe --- /dev/null +++ b/.github/workflows/security_scan_pr.yml @@ -0,0 +1,23 @@ +# Copyright Advanced Micro Devices, Inc. +# SPDX-License-Identifier: MIT +# +# PR-time security scan. Requests human-readable reports only: findings are +# uploaded as a build artifact and printed to the job summary, never to the +# Security tab, so fork PRs (which never receive elevated tokens) behave +# identically to same-repo PRs. See the scheduled counterpart +# (security_scan_weekly.yml) for the SARIF / code-scanning upload. + +name: Security scan (PR) + +on: + pull_request: + +permissions: + contents: read + +jobs: + security: + name: Security scan + uses: ROCm/rocm-security-gh/.github/workflows/security-baseline.yml@ca9c7de9ba875c08d9619319ab81c4587b92ae4e # main as of 2026-08-31 + with: + report_formats: human diff --git a/.github/workflows/security_scan_weekly.yml b/.github/workflows/security_scan_weekly.yml new file mode 100644 index 0000000000..6e8c864192 --- /dev/null +++ b/.github/workflows/security_scan_weekly.yml @@ -0,0 +1,30 @@ +# Copyright Advanced Micro Devices, Inc. +# SPDX-License-Identifier: MIT +# +# Trusted security scan: full-repo scan (scan_mode: all) with SARIF results +# uploaded to the Security tab. `security-events: write` is granted on the +# `uses:` job itself, not just the top-level `permissions:` block above it, +# since a `permissions:` block (wherever declared) implicitly zeroes out +# anything it doesn't list. See the PR-time counterpart +# (security_scan_pr.yml) for the human-readable, non-elevated variant. + +name: Weekly security scan + +on: + schedule: + - cron: "0 10 * * 6" + workflow_dispatch: + +permissions: + contents: read + +jobs: + security: + name: Security scan + permissions: + contents: read + security-events: write + uses: ROCm/rocm-security-gh/.github/workflows/security-baseline.yml@ca9c7de9ba875c08d9619319ab81c4587b92ae4e # main as of 2026-08-31 + with: + scan_mode: all + report_formats: sarif From b4921ec827ed381a4228f8e2cead1bf8106cefb5 Mon Sep 17 00:00:00 2001 From: Ciprian Goea Date: Mon, 31 Aug 2026 19:47:22 +0300 Subject: [PATCH 02/13] use v1.0.0 tag --- .github/workflows/security_scan_pr.yml | 2 +- .github/workflows/security_scan_weekly.yml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/security_scan_pr.yml b/.github/workflows/security_scan_pr.yml index d976ed68fe..2671f5a8ff 100644 --- a/.github/workflows/security_scan_pr.yml +++ b/.github/workflows/security_scan_pr.yml @@ -18,6 +18,6 @@ permissions: jobs: security: name: Security scan - uses: ROCm/rocm-security-gh/.github/workflows/security-baseline.yml@ca9c7de9ba875c08d9619319ab81c4587b92ae4e # main as of 2026-08-31 + uses: ROCm/rocm-security-gh/.github/workflows/security-baseline.yml@ca9c7de9ba875c08d9619319ab81c4587b92ae4e # v1.0.0 with: report_formats: human diff --git a/.github/workflows/security_scan_weekly.yml b/.github/workflows/security_scan_weekly.yml index 6e8c864192..873c8c21b8 100644 --- a/.github/workflows/security_scan_weekly.yml +++ b/.github/workflows/security_scan_weekly.yml @@ -24,7 +24,7 @@ jobs: permissions: contents: read security-events: write - uses: ROCm/rocm-security-gh/.github/workflows/security-baseline.yml@ca9c7de9ba875c08d9619319ab81c4587b92ae4e # main as of 2026-08-31 + uses: ROCm/rocm-security-gh/.github/workflows/security-baseline.yml@ca9c7de9ba875c08d9619319ab81c4587b92ae4e # v1.0.0 with: scan_mode: all report_formats: sarif From 6e6f581e694769133c2f48efada1db4665bf2ca7 Mon Sep 17 00:00:00 2001 From: Ciprian Goea Date: Tue, 1 Sep 2026 15:09:36 +0300 Subject: [PATCH 03/13] update scanners commit id and add config files --- .github/workflows/security_scan_pr.yml | 2 +- .github/workflows/security_scan_weekly.yml | 2 +- bandit.yaml | 14 ++++++++++++++ gitleaks.toml | 14 ++++++++++++++ trivy.yaml | 15 +++++++++++++++ zizmor.yml | 9 +++++++++ 6 files changed, 54 insertions(+), 2 deletions(-) create mode 100644 bandit.yaml create mode 100644 gitleaks.toml create mode 100644 trivy.yaml create mode 100644 zizmor.yml diff --git a/.github/workflows/security_scan_pr.yml b/.github/workflows/security_scan_pr.yml index 2671f5a8ff..6ae9e4d6b0 100644 --- a/.github/workflows/security_scan_pr.yml +++ b/.github/workflows/security_scan_pr.yml @@ -18,6 +18,6 @@ permissions: jobs: security: name: Security scan - uses: ROCm/rocm-security-gh/.github/workflows/security-baseline.yml@ca9c7de9ba875c08d9619319ab81c4587b92ae4e # v1.0.0 + uses: ROCm/rocm-security-gh/.github/workflows/security-baseline.yml@4b25e6bc1cb0b9bbc3c278b2f1c70d8f2f406e20 # v1.0.0 with: report_formats: human diff --git a/.github/workflows/security_scan_weekly.yml b/.github/workflows/security_scan_weekly.yml index 873c8c21b8..08964aef95 100644 --- a/.github/workflows/security_scan_weekly.yml +++ b/.github/workflows/security_scan_weekly.yml @@ -24,7 +24,7 @@ jobs: permissions: contents: read security-events: write - uses: ROCm/rocm-security-gh/.github/workflows/security-baseline.yml@ca9c7de9ba875c08d9619319ab81c4587b92ae4e # v1.0.0 + uses: ROCm/rocm-security-gh/.github/workflows/security-baseline.yml@4b25e6bc1cb0b9bbc3c278b2f1c70d8f2f406e20 # v1.0.0 with: scan_mode: all report_formats: sarif diff --git a/bandit.yaml b/bandit.yaml new file mode 100644 index 0000000000..6df0a50927 --- /dev/null +++ b/bandit.yaml @@ -0,0 +1,14 @@ +# Copyright Advanced Micro Devices, Inc. +# SPDX-License-Identifier: MIT +# +# bandit configuration for Quartz, picked up by the rocm-security-gh +# reusable scanner (.github/workflows/security_scan_pr.yml and +# security_scan_weekly.yml) in place of its own org-wide default. +# Reference: https://bandit.readthedocs.io/en/latest/config.html + +exclude_dirs: + - .git + - .venv + - venv + - release-nightly + - prereleases diff --git a/gitleaks.toml b/gitleaks.toml new file mode 100644 index 0000000000..5235bbe01f --- /dev/null +++ b/gitleaks.toml @@ -0,0 +1,14 @@ +# Copyright Advanced Micro Devices, Inc. +# SPDX-License-Identifier: MIT +# +# gitleaks configuration for Quartz, picked up by the rocm-security-gh +# reusable scanner (.github/workflows/security_scan_pr.yml and +# security_scan_weekly.yml) in place of its own org-wide default. +# Reference: https://github.com/gitleaks/gitleaks/blob/master/config/gitleaks.toml + +title = "Quartz gitleaks config" + +[extend] +# Inherit gitleaks' built-in ruleset (rotations, AWS, GCP, Slack, ...) +# rather than rolling our own detections. +useDefault = true diff --git a/trivy.yaml b/trivy.yaml new file mode 100644 index 0000000000..77ed054964 --- /dev/null +++ b/trivy.yaml @@ -0,0 +1,15 @@ +# Copyright Advanced Micro Devices, Inc. +# SPDX-License-Identifier: MIT +# +# trivy configuration for Quartz, picked up by the rocm-security-gh +# reusable scanner (.github/workflows/security_scan_pr.yml and +# security_scan_weekly.yml) in place of its own org-wide default. +# Reference: https://trivy.dev/latest/docs/references/configuration/config-file/ + +scan: + skip-dirs: + - .git + - .venv + - venv + - release-nightly + - prereleases diff --git a/zizmor.yml b/zizmor.yml new file mode 100644 index 0000000000..d3ee605482 --- /dev/null +++ b/zizmor.yml @@ -0,0 +1,9 @@ +# Copyright Advanced Micro Devices, Inc. +# SPDX-License-Identifier: MIT +# +# zizmor configuration for Quartz, picked up by the rocm-security-gh +# reusable scanner (.github/workflows/security_scan_pr.yml and +# security_scan_weekly.yml) in place of its own org-wide default. +# Reference: https://docs.zizmor.sh/configuration/ + +rules: {} From 9357f74e3333831df0e309c1087cf2cbd4e04edb Mon Sep 17 00:00:00 2001 From: Ciprian Goea Date: Wed, 9 Sep 2026 16:25:08 +0300 Subject: [PATCH 04/13] bumpo sec scan commit id --- .github/workflows/security_scan_pr.yml | 2 +- .github/workflows/security_scan_weekly.yml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/security_scan_pr.yml b/.github/workflows/security_scan_pr.yml index 6ae9e4d6b0..6ee1205c7a 100644 --- a/.github/workflows/security_scan_pr.yml +++ b/.github/workflows/security_scan_pr.yml @@ -18,6 +18,6 @@ permissions: jobs: security: name: Security scan - uses: ROCm/rocm-security-gh/.github/workflows/security-baseline.yml@4b25e6bc1cb0b9bbc3c278b2f1c70d8f2f406e20 # v1.0.0 + uses: ROCm/rocm-security-gh/.github/workflows/security-baseline.yml@31ec6f8dd59194dc8a94436865342fd00dea73fd # v1.0.0 with: report_formats: human diff --git a/.github/workflows/security_scan_weekly.yml b/.github/workflows/security_scan_weekly.yml index 08964aef95..efadf7c95e 100644 --- a/.github/workflows/security_scan_weekly.yml +++ b/.github/workflows/security_scan_weekly.yml @@ -24,7 +24,7 @@ jobs: permissions: contents: read security-events: write - uses: ROCm/rocm-security-gh/.github/workflows/security-baseline.yml@4b25e6bc1cb0b9bbc3c278b2f1c70d8f2f406e20 # v1.0.0 + uses: ROCm/rocm-security-gh/.github/workflows/security-baseline.yml@31ec6f8dd59194dc8a94436865342fd00dea73fd # v1.0.0 with: scan_mode: all report_formats: sarif From f5f757cec163858797fd433e80a70815275acfe1 Mon Sep 17 00:00:00 2001 From: Ciprian Goea Date: Wed, 9 Sep 2026 16:39:40 +0300 Subject: [PATCH 05/13] ci: scope GitHub App tokens to fix zizmor high findings --- .github/actions/notify_quartz/action.yml | 4 ++++ .github/workflows/receive_therock_data.yml | 3 +++ .github/workflows/sync_develop_to_main.yml | 3 +++ 3 files changed, 10 insertions(+) diff --git a/.github/actions/notify_quartz/action.yml b/.github/actions/notify_quartz/action.yml index f3000a5686..ae39f9e0a2 100644 --- a/.github/actions/notify_quartz/action.yml +++ b/.github/actions/notify_quartz/action.yml @@ -96,6 +96,10 @@ runs: client-id: ${{ inputs.gh_app_client_id }} private-key: ${{ inputs.gh_app_private_key }} repositories: ${{ inputs.quartz_repo }} + # Scoped to quartz_repo above; the only call this token makes there + # is the workflow_dispatch to trigger ingestion, so cap it to that + # instead of inheriting the app installation's full permission set. + permission-actions: write - name: Notify Quartz if: steps.app-token.outputs.token != '' diff --git a/.github/workflows/receive_therock_data.yml b/.github/workflows/receive_therock_data.yml index 88bc550728..e8b0acb956 100644 --- a/.github/workflows/receive_therock_data.yml +++ b/.github/workflows/receive_therock_data.yml @@ -40,6 +40,9 @@ jobs: client-id: ${{ secrets.GH_APP_QUARTZ_SYNC_CID }} private-key: ${{ secrets.GH_APP_QUARTZ_SYNC_PRIVATE_KEY }} repositories: Quartz + # Used only to push the status.json commit below; cap it there + # instead of inheriting the app installation's full permission set. + permission-contents: write - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: diff --git a/.github/workflows/sync_develop_to_main.yml b/.github/workflows/sync_develop_to_main.yml index 800d78953e..295d29c085 100644 --- a/.github/workflows/sync_develop_to_main.yml +++ b/.github/workflows/sync_develop_to_main.yml @@ -27,6 +27,9 @@ jobs: client-id: ${{ secrets.GH_APP_QUARTZ_SYNC_CID }} private-key: ${{ secrets.GH_APP_QUARTZ_SYNC_PRIVATE_KEY }} repositories: Quartz + # Used only to push the develop->main merge below; cap it there + # instead of inheriting the app installation's full permission set. + permission-contents: write - name: Checkout main uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 From 338821e2f7cdfe4a611daf427a8a69e362c8234c Mon Sep 17 00:00:00 2001 From: Ciprian Goea Date: Wed, 9 Sep 2026 16:43:49 +0300 Subject: [PATCH 06/13] remove not needed comments --- .github/actions/notify_quartz/action.yml | 3 --- .github/workflows/receive_therock_data.yml | 2 -- .github/workflows/sync_develop_to_main.yml | 2 -- 3 files changed, 7 deletions(-) diff --git a/.github/actions/notify_quartz/action.yml b/.github/actions/notify_quartz/action.yml index ae39f9e0a2..14c6db641d 100644 --- a/.github/actions/notify_quartz/action.yml +++ b/.github/actions/notify_quartz/action.yml @@ -96,9 +96,6 @@ runs: client-id: ${{ inputs.gh_app_client_id }} private-key: ${{ inputs.gh_app_private_key }} repositories: ${{ inputs.quartz_repo }} - # Scoped to quartz_repo above; the only call this token makes there - # is the workflow_dispatch to trigger ingestion, so cap it to that - # instead of inheriting the app installation's full permission set. permission-actions: write - name: Notify Quartz diff --git a/.github/workflows/receive_therock_data.yml b/.github/workflows/receive_therock_data.yml index e8b0acb956..52ddf8babe 100644 --- a/.github/workflows/receive_therock_data.yml +++ b/.github/workflows/receive_therock_data.yml @@ -40,8 +40,6 @@ jobs: client-id: ${{ secrets.GH_APP_QUARTZ_SYNC_CID }} private-key: ${{ secrets.GH_APP_QUARTZ_SYNC_PRIVATE_KEY }} repositories: Quartz - # Used only to push the status.json commit below; cap it there - # instead of inheriting the app installation's full permission set. permission-contents: write - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 diff --git a/.github/workflows/sync_develop_to_main.yml b/.github/workflows/sync_develop_to_main.yml index 295d29c085..47d041a1f0 100644 --- a/.github/workflows/sync_develop_to_main.yml +++ b/.github/workflows/sync_develop_to_main.yml @@ -27,8 +27,6 @@ jobs: client-id: ${{ secrets.GH_APP_QUARTZ_SYNC_CID }} private-key: ${{ secrets.GH_APP_QUARTZ_SYNC_PRIVATE_KEY }} repositories: Quartz - # Used only to push the develop->main merge below; cap it there - # instead of inheriting the app installation's full permission set. permission-contents: write - name: Checkout main From 3cf13a95e4160c66c7d74c238d954403766596aa Mon Sep 17 00:00:00 2001 From: Ciprian Goea Date: Wed, 9 Sep 2026 18:00:28 +0300 Subject: [PATCH 07/13] Apply suggestion from @HereThereBeDragons Co-authored-by: Laura Promberger --- bandit.yaml | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/bandit.yaml b/bandit.yaml index 6df0a50927..7f6e1e4035 100644 --- a/bandit.yaml +++ b/bandit.yaml @@ -11,4 +11,5 @@ exclude_dirs: - .venv - venv - release-nightly - - prereleases + - prerelease + - nightly From 31fd8b72cc63a399446650567c8b2b155d654de9 Mon Sep 17 00:00:00 2001 From: Ciprian Goea Date: Wed, 9 Sep 2026 18:01:43 +0300 Subject: [PATCH 08/13] rename extension for all configs --- bandit.yaml => bandit.yml | 0 trivy.yaml => trivy.yml | 0 2 files changed, 0 insertions(+), 0 deletions(-) rename bandit.yaml => bandit.yml (100%) rename trivy.yaml => trivy.yml (100%) diff --git a/bandit.yaml b/bandit.yml similarity index 100% rename from bandit.yaml rename to bandit.yml diff --git a/trivy.yaml b/trivy.yml similarity index 100% rename from trivy.yaml rename to trivy.yml From f149097de9d48887a21fd20df7b1ddcef5ce0655 Mon Sep 17 00:00:00 2001 From: Ciprian Goea Date: Wed, 9 Sep 2026 18:08:19 +0300 Subject: [PATCH 09/13] add missing concurrency group --- .github/workflows/security_scan_pr.yml | 18 ++++++++++-------- .github/workflows/security_scan_weekly.yml | 17 ++++++++--------- 2 files changed, 18 insertions(+), 17 deletions(-) diff --git a/.github/workflows/security_scan_pr.yml b/.github/workflows/security_scan_pr.yml index 6ee1205c7a..96db3671a9 100644 --- a/.github/workflows/security_scan_pr.yml +++ b/.github/workflows/security_scan_pr.yml @@ -1,13 +1,12 @@ # Copyright Advanced Micro Devices, Inc. # SPDX-License-Identifier: MIT # -# PR-time security scan. Requests human-readable reports only: findings are -# uploaded as a build artifact and printed to the job summary, never to the -# Security tab, so fork PRs (which never receive elevated tokens) behave -# identically to same-repo PRs. See the scheduled counterpart -# (security_scan_weekly.yml) for the SARIF / code-scanning upload. +# Pre-commit security gate: fast, PR-side security scanners that run on +# every pull request. The security counterpart to `pre-commit.yml`. The +# set of scanners lives in `security-baseline.yml`, so scanners coming +# online are picked up here without touching this file. -name: Security scan (PR) +name: PR security scan on: pull_request: @@ -15,9 +14,12 @@ on: permissions: contents: read +concurrency: + group: ${{ github.workflow }}-${{ github.event.pull_request.number }} + cancel-in-progress: true + jobs: security: - name: Security scan - uses: ROCm/rocm-security-gh/.github/workflows/security-baseline.yml@31ec6f8dd59194dc8a94436865342fd00dea73fd # v1.0.0 + uses: $/.github/workflows/security-baseline.yml with: report_formats: human diff --git a/.github/workflows/security_scan_weekly.yml b/.github/workflows/security_scan_weekly.yml index efadf7c95e..6fcefe34da 100644 --- a/.github/workflows/security_scan_weekly.yml +++ b/.github/workflows/security_scan_weekly.yml @@ -1,16 +1,15 @@ # Copyright Advanced Micro Devices, Inc. # SPDX-License-Identifier: MIT # -# Trusted security scan: full-repo scan (scan_mode: all) with SARIF results -# uploaded to the Security tab. `security-events: write` is granted on the -# `uses:` job itself, not just the top-level `permissions:` block above it, -# since a `permissions:` block (wherever declared) implicitly zeroes out -# anything it doesn't list. See the PR-time counterpart -# (security_scan_pr.yml) for the human-readable, non-elevated variant. +# Weekly security scan: runs on a fixed cadence and pushes SARIF findings +# to the repository's code-scanning Security tab. Complements +# `pr-security-scan.yml`, which scans only what changed in a PR and +# uploads reviewer-readable artifacts for in-review browsing. -name: Weekly security scan +name: Security scan (Weekly) on: + # Run every Saturday at 10:00 UTC. schedule: - cron: "0 10 * * 6" workflow_dispatch: @@ -20,11 +19,11 @@ permissions: jobs: security: - name: Security scan + # Only the job that uploads SARIF gets write access to code scanning. permissions: contents: read security-events: write - uses: ROCm/rocm-security-gh/.github/workflows/security-baseline.yml@31ec6f8dd59194dc8a94436865342fd00dea73fd # v1.0.0 + uses: $/.github/workflows/security-baseline.yml with: scan_mode: all report_formats: sarif From acbcc86344b86d56aeeacb31692ce314c6371155 Mon Sep 17 00:00:00 2001 From: Ciprian Goea Date: Wed, 9 Sep 2026 18:13:38 +0300 Subject: [PATCH 10/13] fix uses call --- .github/workflows/security_scan_pr.yml | 2 +- .github/workflows/security_scan_weekly.yml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/security_scan_pr.yml b/.github/workflows/security_scan_pr.yml index 96db3671a9..38682b8af3 100644 --- a/.github/workflows/security_scan_pr.yml +++ b/.github/workflows/security_scan_pr.yml @@ -20,6 +20,6 @@ concurrency: jobs: security: - uses: $/.github/workflows/security-baseline.yml + uses: ROCm/rocm-security-gh/.github/workflows/security-baseline.yml@31ec6f8dd59194dc8a94436865342fd00dea73fd # v1.0.0 with: report_formats: human diff --git a/.github/workflows/security_scan_weekly.yml b/.github/workflows/security_scan_weekly.yml index 6fcefe34da..fbdd87c247 100644 --- a/.github/workflows/security_scan_weekly.yml +++ b/.github/workflows/security_scan_weekly.yml @@ -23,7 +23,7 @@ jobs: permissions: contents: read security-events: write - uses: $/.github/workflows/security-baseline.yml + uses: ROCm/rocm-security-gh/.github/workflows/security-baseline.yml@31ec6f8dd59194dc8a94436865342fd00dea73fd # v1.0.0 with: scan_mode: all report_formats: sarif From 3d9a85bf76d3f311ca0c95e77c7d347eb20cc795 Mon Sep 17 00:00:00 2001 From: Ciprian Goea Date: Wed, 9 Sep 2026 19:11:37 +0300 Subject: [PATCH 11/13] fix: pre-commit whitespace and register security scan workflows - Strip trailing whitespace in bandit.yml (pre-commit failure). - Merging develop pulled in #100's stricter workflow-partition test; register the new security_scan_pr.yml / security_scan_weekly.yml workflows in _EXCLUDED_WORKFLOWS since they are Quartz-local CI plumbing, not TheRock/rockrel producer workflows that report to notify_quartz. --- bandit.yml | 2 +- scripts/receive_therock/tests/therock_workflow_registry_test.py | 2 ++ 2 files changed, 3 insertions(+), 1 deletion(-) diff --git a/bandit.yml b/bandit.yml index 7f6e1e4035..74c28e436b 100644 --- a/bandit.yml +++ b/bandit.yml @@ -12,4 +12,4 @@ exclude_dirs: - venv - release-nightly - prerelease - - nightly + - nightly diff --git a/scripts/receive_therock/tests/therock_workflow_registry_test.py b/scripts/receive_therock/tests/therock_workflow_registry_test.py index 2139b7beb1..0ef0d2ac10 100644 --- a/scripts/receive_therock/tests/therock_workflow_registry_test.py +++ b/scripts/receive_therock/tests/therock_workflow_registry_test.py @@ -89,6 +89,8 @@ "bender.yml", "sync_develop_to_main.yml", "pre_commit.yml", + "security_scan_pr.yml", + "security_scan_weekly.yml", } ) From 2d02a29133bd364158deeedff13eef012333a6b1 Mon Sep 17 00:00:00 2001 From: Ciprian Goea Date: Thu, 10 Sep 2026 12:37:03 +0300 Subject: [PATCH 12/13] docs: document security scanners and how to run them locally --- CONTRIBUTING.md | 44 ++++++++++++++++++++++++++++++++++++++++++++ SECURITY.md | 42 ++++++++++++++++++++++++++++++++++++++++++ 2 files changed, 86 insertions(+) diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 8801a0deda..50c79923c3 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -50,3 +50,47 @@ Notes: is titled `Merge develop () into main` and records the synced commit's hash, subject, author, and date in its body, so it is easy to tell the merge commit apart from the original `develop` commit. + +## Security scanners + +Separately from the correctness checks covered by TheRock's `CONTRIBUTING.md`, +this repository scans for secrets, unsafe Python, and workflow +vulnerabilities. These run in CI via +[`security_scan_pr.yml`](.github/workflows/security_scan_pr.yml), which calls +the shared [`ROCm/rocm-security-gh`](https://github.com/ROCm/rocm-security-gh) +reusable workflow. See +[the automated security scanning section in `SECURITY.md`](SECURITY.md#automated-security-scanning) +for how the PR-time and weekly workflows fit together. + +Each scanner is runnable locally against the same configuration CI uses, +which is faster than pushing a commit to see what CI says. The +configurations live at the repo root: + +```bash +# Secrets, over the full git history (installed separately, see gitleaks docs). +gitleaks detect --source . --config gitleaks.toml --redact --verbose --no-banner + +# Secrets, working tree only. Much faster, and usually what you want locally. +gitleaks detect --source . --config gitleaks.toml --redact --no-banner --no-git + +# Unsafe patterns in Python (pip install bandit). +bandit --configfile bandit.yml --severity-level low --recursive . + +# GitHub Actions workflow vulnerabilities (pip install zizmor). +zizmor --persona regular --config zizmor.yml . + +# Dependency vulnerabilities and misconfigurations (see trivy docs). +trivy fs --config trivy.yml --severity LOW,MEDIUM,HIGH,CRITICAL --scanners misconfig,vuln . +``` + +> [!NOTE] +> These commands report every severity, while CI only fails on `HIGH` (and +> `CRITICAL` for trivy). Expect more output locally than a red CI check implies. +> +> The commands also scan the whole repository, while pull request runs default +> to scanning only what the pull request changed. A full-history `gitleaks` run +> in particular reports pre-existing findings that the pull request check does +> not. + +CodeQL is not in the list above: it runs in CI only, against the org-wide +default configuration (Quartz does not override it locally). diff --git a/SECURITY.md b/SECURITY.md index cf466d848a..e8eebdf753 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -13,3 +13,45 @@ We aim to acknowledge reports within 1 business day. ## Scope This policy covers code and configuration in this repository. For vulnerabilities in third-party dependencies, report upstream. For AMD product issues unrelated to this repo, use the [AMD Product Security portal](https://www.amd.com/en/resources/product-security.html). + +## Automated security scanning + +Alongside the reporting path above, this repository is scanned automatically. +The scanners are not implemented here: Quartz calls the shared +[`ROCm/rocm-security-gh`](https://github.com/ROCm/rocm-security-gh) +`security-baseline.yml` reusable workflow, so the scanner versions and +behavior are maintained centrally for ROCm, and this repository supplies only +its own configuration (the `*.yml` / `*.toml` files at the repo root). + +| Scanner | Looks for | Configuration | +| ------------------------------------------------ | -------------------------------------------------------- | ------------------------------------ | +| [gitleaks](https://github.com/gitleaks/gitleaks) | Secrets and credentials in tracked files and git history | [`gitleaks.toml`](gitleaks.toml) | +| [bandit](https://bandit.readthedocs.io/) | Unsafe patterns in our Python scripts | [`bandit.yml`](bandit.yml) | +| [zizmor](https://docs.zizmor.sh/) | GitHub Actions workflow vulnerabilities | [`zizmor.yml`](zizmor.yml) | +| [trivy](https://trivy.dev/) | Dependency vulnerabilities and misconfigurations | [`trivy.yml`](trivy.yml) | +| [CodeQL](https://codeql.github.com/) | Semantic code analysis of our Python | org-wide default (no local override) | + +Two workflows run them, and where a finding shows up depends on which one +produced it: + +- [`security_scan_pr.yml`](.github/workflows/security_scan_pr.yml) runs on + every pull request, scoped to what that pull request changed. It reports in + the job summary and a build artifact, and deliberately does not upload to + the Security tab, so pull requests from forks behave the same as those from + branches in this repository. +- [`security_scan_weekly.yml`](.github/workflows/security_scan_weekly.yml) + runs on a schedule across the whole repository and uploads SARIF to this + repository's Security tab, which is the authoritative view of the current + state. Quartz is a monorepo-adjacent, low-churn repository, so a weekly + cadence (rather than on every push to `develop`/`main`) is enough to keep + the Security tab current without adding a scan to every merge. + +> [!IMPORTANT] +> A finding from these scanners is not a vulnerability report. If a scanner +> finding turns out to be an exploitable vulnerability in shipped ROCm +> software, report it through the AMD Product Security portal above rather +> than in a public issue or pull request. + +Contributors can run every scanner locally against the same configuration CI +uses; see +[the security scanners section in `CONTRIBUTING.md`](CONTRIBUTING.md#security-scanners). From b578e1502eaf4ed71ba51718f2e5e2c6e5b2142f Mon Sep 17 00:00:00 2001 From: Ciprian Goea Date: Thu, 10 Sep 2026 15:30:43 +0300 Subject: [PATCH 13/13] address comments from reviewer --- .github/workflows/security_scan_pr.yml | 2 +- CONTRIBUTING.md | 8 ++++---- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/.github/workflows/security_scan_pr.yml b/.github/workflows/security_scan_pr.yml index 38682b8af3..62061b21c9 100644 --- a/.github/workflows/security_scan_pr.yml +++ b/.github/workflows/security_scan_pr.yml @@ -6,7 +6,7 @@ # set of scanners lives in `security-baseline.yml`, so scanners coming # online are picked up here without touching this file. -name: PR security scan +name: Security scan (PR) on: pull_request: diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 50c79923c3..c410045f7b 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -67,12 +67,12 @@ which is faster than pushing a commit to see what CI says. The configurations live at the repo root: ```bash -# Secrets, over the full git history (installed separately, see gitleaks docs). -gitleaks detect --source . --config gitleaks.toml --redact --verbose --no-banner - -# Secrets, working tree only. Much faster, and usually what you want locally. +# Secrets, working tree only. Recommended much faster, and usually what you want locally. gitleaks detect --source . --config gitleaks.toml --redact --no-banner --no-git +# Secrets, over the full git history. Takes longer than the working tree one above. +gitleaks detect --source . --config gitleaks.toml --redact --verbose --no-banner + # Unsafe patterns in Python (pip install bandit). bandit --configfile bandit.yml --severity-level low --recursive .