-
Notifications
You must be signed in to change notification settings - Fork 1
ci: add security scanners to Quartz #90
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
b9201ee
b4921ec
6e6f581
9357f74
51909c1
f5f757c
338821e
3cf13a9
31fd8b7
23b94ca
f149097
acbcc86
a898078
3d9a85b
2d02a29
b578e15
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,25 @@ | ||
| # Copyright Advanced Micro Devices, Inc. | ||
| # SPDX-License-Identifier: MIT | ||
| # | ||
| # Pre-commit security gate: fast, PR-side security scanners that run on | ||
| # every pull request. The security counterpart to `pre-commit.yml`. The | ||
| # set of scanners lives in `security-baseline.yml`, so scanners coming | ||
| # online are picked up here without touching this file. | ||
|
|
||
| name: Security scan (PR) | ||
|
|
||
| on: | ||
| pull_request: | ||
|
|
||
| permissions: | ||
| contents: read | ||
|
|
||
| concurrency: | ||
| group: ${{ github.workflow }}-${{ github.event.pull_request.number }} | ||
| cancel-in-progress: true | ||
|
|
||
| jobs: | ||
| security: | ||
| uses: ROCm/rocm-security-gh/.github/workflows/security-baseline.yml@31ec6f8dd59194dc8a94436865342fd00dea73fd # v1.0.0 | ||
| with: | ||
| report_formats: human | ||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,29 @@ | ||
| # Copyright Advanced Micro Devices, Inc. | ||
| # SPDX-License-Identifier: MIT | ||
| # | ||
| # Weekly security scan: runs on a fixed cadence and pushes SARIF findings | ||
| # to the repository's code-scanning Security tab. Complements | ||
| # `pr-security-scan.yml`, which scans only what changed in a PR and | ||
| # uploads reviewer-readable artifacts for in-review browsing. | ||
|
|
||
| name: Security scan (Weekly) | ||
|
|
||
| on: | ||
| # Run every Saturday at 10:00 UTC. | ||
| schedule: | ||
| - cron: "0 10 * * 6" | ||
| workflow_dispatch: | ||
|
|
||
| permissions: | ||
| contents: read | ||
|
|
||
| jobs: | ||
| security: | ||
| # Only the job that uploads SARIF gets write access to code scanning. | ||
| permissions: | ||
| contents: read | ||
| security-events: write | ||
| uses: ROCm/rocm-security-gh/.github/workflows/security-baseline.yml@31ec6f8dd59194dc8a94436865342fd00dea73fd # v1.0.0 | ||
| with: | ||
| scan_mode: all | ||
| report_formats: sarif |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -50,3 +50,47 @@ Notes: | |
| is titled `Merge develop (<hash>) into main` and records the synced commit's | ||
| hash, subject, author, and date in its body, so it is easy to tell the merge | ||
| commit apart from the original `develop` commit. | ||
|
|
||
| ## Security scanners | ||
|
|
||
| Separately from the correctness checks covered by TheRock's `CONTRIBUTING.md`, | ||
| this repository scans for secrets, unsafe Python, and workflow | ||
| vulnerabilities. These run in CI via | ||
| [`security_scan_pr.yml`](.github/workflows/security_scan_pr.yml), which calls | ||
| the shared [`ROCm/rocm-security-gh`](https://github.com/ROCm/rocm-security-gh) | ||
| reusable workflow. See | ||
| [the automated security scanning section in `SECURITY.md`](SECURITY.md#automated-security-scanning) | ||
| for how the PR-time and weekly workflows fit together. | ||
|
|
||
| Each scanner is runnable locally against the same configuration CI uses, | ||
| which is faster than pushing a commit to see what CI says. The | ||
| configurations live at the repo root: | ||
|
|
||
| ```bash | ||
| # Secrets, working tree only. Recommended much faster, and usually what you want locally. | ||
| gitleaks detect --source . --config gitleaks.toml --redact --no-banner --no-git | ||
|
|
||
| # Secrets, over the full git history. Takes longer than the working tree one above. | ||
| gitleaks detect --source . --config gitleaks.toml --redact --verbose --no-banner | ||
|
|
||
| # Unsafe patterns in Python (pip install bandit). | ||
| bandit --configfile bandit.yml --severity-level low --recursive . | ||
|
|
||
| # GitHub Actions workflow vulnerabilities (pip install zizmor). | ||
| zizmor --persona regular --config zizmor.yml . | ||
|
|
||
| # Dependency vulnerabilities and misconfigurations (see trivy docs). | ||
| trivy fs --config trivy.yml --severity LOW,MEDIUM,HIGH,CRITICAL --scanners misconfig,vuln . | ||
| ``` | ||
|
|
||
| > [!NOTE] | ||
| > These commands report every severity, while CI only fails on `HIGH` (and | ||
| > `CRITICAL` for trivy). Expect more output locally than a red CI check implies. | ||
| > | ||
| > The commands also scan the whole repository, while pull request runs default | ||
| > to scanning only what the pull request changed. A full-history `gitleaks` run | ||
| > in particular reports pre-existing findings that the pull request check does | ||
| > not. | ||
|
|
||
| CodeQL is not in the list above: it runs in CI only, against the org-wide | ||
|
Collaborator
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. we dont have any codeql yet?
Contributor
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. we don't. it will come with the scanners. |
||
| default configuration (Quartz does not override it locally). | ||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,15 @@ | ||
| # Copyright Advanced Micro Devices, Inc. | ||
| # SPDX-License-Identifier: MIT | ||
| # | ||
| # bandit configuration for Quartz, picked up by the rocm-security-gh | ||
| # reusable scanner (.github/workflows/security_scan_pr.yml and | ||
| # security_scan_weekly.yml) in place of its own org-wide default. | ||
| # Reference: https://bandit.readthedocs.io/en/latest/config.html | ||
|
|
||
| exclude_dirs: | ||
| - .git | ||
| - .venv | ||
| - venv | ||
| - release-nightly | ||
| - prerelease | ||
| - nightly |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,14 @@ | ||
| # Copyright Advanced Micro Devices, Inc. | ||
| # SPDX-License-Identifier: MIT | ||
| # | ||
| # gitleaks configuration for Quartz, picked up by the rocm-security-gh | ||
| # reusable scanner (.github/workflows/security_scan_pr.yml and | ||
| # security_scan_weekly.yml) in place of its own org-wide default. | ||
| # Reference: https://github.com/gitleaks/gitleaks/blob/master/config/gitleaks.toml | ||
|
|
||
| title = "Quartz gitleaks config" | ||
|
|
||
| [extend] | ||
| # Inherit gitleaks' built-in ruleset (rotations, AWS, GCP, Slack, ...) | ||
| # rather than rolling our own detections. | ||
| useDefault = true |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,15 @@ | ||
| # Copyright Advanced Micro Devices, Inc. | ||
| # SPDX-License-Identifier: MIT | ||
| # | ||
| # trivy configuration for Quartz, picked up by the rocm-security-gh | ||
| # reusable scanner (.github/workflows/security_scan_pr.yml and | ||
| # security_scan_weekly.yml) in place of its own org-wide default. | ||
| # Reference: https://trivy.dev/latest/docs/references/configuration/config-file/ | ||
|
|
||
| scan: | ||
| skip-dirs: | ||
| - .git | ||
| - .venv | ||
| - venv | ||
| - release-nightly | ||
| - prereleases |
|
Collaborator
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. yaml vs yml? |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,9 @@ | ||
| # Copyright Advanced Micro Devices, Inc. | ||
| # SPDX-License-Identifier: MIT | ||
| # | ||
| # zizmor configuration for Quartz, picked up by the rocm-security-gh | ||
| # reusable scanner (.github/workflows/security_scan_pr.yml and | ||
| # security_scan_weekly.yml) in place of its own org-wide default. | ||
| # Reference: https://docs.zizmor.sh/configuration/ | ||
|
|
||
| rules: {} |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
concurrency block?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
added now