Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .github/actions/notify_quartz/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -96,6 +96,7 @@ runs:
client-id: ${{ inputs.gh_app_client_id }}
private-key: ${{ inputs.gh_app_private_key }}
repositories: ${{ inputs.quartz_repo }}
permission-actions: write

- name: Notify Quartz
if: steps.app-token.outputs.token != ''
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/receive_therock_data.yml
Original file line number Diff line number Diff line change
Expand Up @@ -40,6 +40,7 @@ jobs:
client-id: ${{ secrets.GH_APP_QUARTZ_SYNC_CID }}
private-key: ${{ secrets.GH_APP_QUARTZ_SYNC_PRIVATE_KEY }}
repositories: Quartz
permission-contents: write

- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
Expand Down
25 changes: 25 additions & 0 deletions .github/workflows/security_scan_pr.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,25 @@
# Copyright Advanced Micro Devices, Inc.
# SPDX-License-Identifier: MIT
#
# Pre-commit security gate: fast, PR-side security scanners that run on
# every pull request. The security counterpart to `pre-commit.yml`. The
# set of scanners lives in `security-baseline.yml`, so scanners coming
# online are picked up here without touching this file.

name: Security scan (PR)

on:
pull_request:

permissions:
contents: read

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

concurrency block?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

added now


concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number }}
cancel-in-progress: true

jobs:
security:
uses: ROCm/rocm-security-gh/.github/workflows/security-baseline.yml@31ec6f8dd59194dc8a94436865342fd00dea73fd # v1.0.0
with:
report_formats: human
29 changes: 29 additions & 0 deletions .github/workflows/security_scan_weekly.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,29 @@
# Copyright Advanced Micro Devices, Inc.
# SPDX-License-Identifier: MIT
#
# Weekly security scan: runs on a fixed cadence and pushes SARIF findings
# to the repository's code-scanning Security tab. Complements
# `pr-security-scan.yml`, which scans only what changed in a PR and
# uploads reviewer-readable artifacts for in-review browsing.

name: Security scan (Weekly)

on:
# Run every Saturday at 10:00 UTC.
schedule:
- cron: "0 10 * * 6"
workflow_dispatch:

permissions:
contents: read

jobs:
security:
# Only the job that uploads SARIF gets write access to code scanning.
permissions:
contents: read
security-events: write
uses: ROCm/rocm-security-gh/.github/workflows/security-baseline.yml@31ec6f8dd59194dc8a94436865342fd00dea73fd # v1.0.0
with:
scan_mode: all
report_formats: sarif
1 change: 1 addition & 0 deletions .github/workflows/sync_develop_to_main.yml
Original file line number Diff line number Diff line change
Expand Up @@ -27,6 +27,7 @@ jobs:
client-id: ${{ secrets.GH_APP_QUARTZ_SYNC_CID }}
private-key: ${{ secrets.GH_APP_QUARTZ_SYNC_PRIVATE_KEY }}
repositories: Quartz
permission-contents: write

- name: Checkout main
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
Expand Down
44 changes: 44 additions & 0 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -50,3 +50,47 @@ Notes:
is titled `Merge develop (<hash>) into main` and records the synced commit's
hash, subject, author, and date in its body, so it is easy to tell the merge
commit apart from the original `develop` commit.

## Security scanners

Separately from the correctness checks covered by TheRock's `CONTRIBUTING.md`,
this repository scans for secrets, unsafe Python, and workflow
vulnerabilities. These run in CI via
[`security_scan_pr.yml`](.github/workflows/security_scan_pr.yml), which calls
the shared [`ROCm/rocm-security-gh`](https://github.com/ROCm/rocm-security-gh)
reusable workflow. See
[the automated security scanning section in `SECURITY.md`](SECURITY.md#automated-security-scanning)
for how the PR-time and weekly workflows fit together.

Each scanner is runnable locally against the same configuration CI uses,
which is faster than pushing a commit to see what CI says. The
configurations live at the repo root:

```bash
# Secrets, working tree only. Recommended much faster, and usually what you want locally.
gitleaks detect --source . --config gitleaks.toml --redact --no-banner --no-git

# Secrets, over the full git history. Takes longer than the working tree one above.
gitleaks detect --source . --config gitleaks.toml --redact --verbose --no-banner

# Unsafe patterns in Python (pip install bandit).
bandit --configfile bandit.yml --severity-level low --recursive .

# GitHub Actions workflow vulnerabilities (pip install zizmor).
zizmor --persona regular --config zizmor.yml .

# Dependency vulnerabilities and misconfigurations (see trivy docs).
trivy fs --config trivy.yml --severity LOW,MEDIUM,HIGH,CRITICAL --scanners misconfig,vuln .
```

> [!NOTE]
> These commands report every severity, while CI only fails on `HIGH` (and
> `CRITICAL` for trivy). Expect more output locally than a red CI check implies.
>
> The commands also scan the whole repository, while pull request runs default
> to scanning only what the pull request changed. A full-history `gitleaks` run
> in particular reports pre-existing findings that the pull request check does
> not.

CodeQL is not in the list above: it runs in CI only, against the org-wide

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

we dont have any codeql yet?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

we don't. it will come with the scanners.

default configuration (Quartz does not override it locally).
42 changes: 42 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -13,3 +13,45 @@ We aim to acknowledge reports within 1 business day.
## Scope

This policy covers code and configuration in this repository. For vulnerabilities in third-party dependencies, report upstream. For AMD product issues unrelated to this repo, use the [AMD Product Security portal](https://www.amd.com/en/resources/product-security.html).

## Automated security scanning

Alongside the reporting path above, this repository is scanned automatically.
The scanners are not implemented here: Quartz calls the shared
[`ROCm/rocm-security-gh`](https://github.com/ROCm/rocm-security-gh)
`security-baseline.yml` reusable workflow, so the scanner versions and
behavior are maintained centrally for ROCm, and this repository supplies only
its own configuration (the `*.yml` / `*.toml` files at the repo root).

| Scanner | Looks for | Configuration |
| ------------------------------------------------ | -------------------------------------------------------- | ------------------------------------ |
| [gitleaks](https://github.com/gitleaks/gitleaks) | Secrets and credentials in tracked files and git history | [`gitleaks.toml`](gitleaks.toml) |
| [bandit](https://bandit.readthedocs.io/) | Unsafe patterns in our Python scripts | [`bandit.yml`](bandit.yml) |
| [zizmor](https://docs.zizmor.sh/) | GitHub Actions workflow vulnerabilities | [`zizmor.yml`](zizmor.yml) |
| [trivy](https://trivy.dev/) | Dependency vulnerabilities and misconfigurations | [`trivy.yml`](trivy.yml) |
| [CodeQL](https://codeql.github.com/) | Semantic code analysis of our Python | org-wide default (no local override) |

Two workflows run them, and where a finding shows up depends on which one
produced it:

- [`security_scan_pr.yml`](.github/workflows/security_scan_pr.yml) runs on
every pull request, scoped to what that pull request changed. It reports in
the job summary and a build artifact, and deliberately does not upload to
the Security tab, so pull requests from forks behave the same as those from
branches in this repository.
- [`security_scan_weekly.yml`](.github/workflows/security_scan_weekly.yml)
runs on a schedule across the whole repository and uploads SARIF to this
repository's Security tab, which is the authoritative view of the current
state. Quartz is a monorepo-adjacent, low-churn repository, so a weekly
cadence (rather than on every push to `develop`/`main`) is enough to keep
the Security tab current without adding a scan to every merge.

> [!IMPORTANT]
> A finding from these scanners is not a vulnerability report. If a scanner
> finding turns out to be an exploitable vulnerability in shipped ROCm
> software, report it through the AMD Product Security portal above rather
> than in a public issue or pull request.

Contributors can run every scanner locally against the same configuration CI
uses; see
[the security scanners section in `CONTRIBUTING.md`](CONTRIBUTING.md#security-scanners).
15 changes: 15 additions & 0 deletions bandit.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
# Copyright Advanced Micro Devices, Inc.
# SPDX-License-Identifier: MIT
#
# bandit configuration for Quartz, picked up by the rocm-security-gh
# reusable scanner (.github/workflows/security_scan_pr.yml and
# security_scan_weekly.yml) in place of its own org-wide default.
# Reference: https://bandit.readthedocs.io/en/latest/config.html

exclude_dirs:
- .git
- .venv
- venv
- release-nightly
- prerelease
- nightly
14 changes: 14 additions & 0 deletions gitleaks.toml
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
# Copyright Advanced Micro Devices, Inc.
# SPDX-License-Identifier: MIT
#
# gitleaks configuration for Quartz, picked up by the rocm-security-gh
# reusable scanner (.github/workflows/security_scan_pr.yml and
# security_scan_weekly.yml) in place of its own org-wide default.
# Reference: https://github.com/gitleaks/gitleaks/blob/master/config/gitleaks.toml

title = "Quartz gitleaks config"

[extend]
# Inherit gitleaks' built-in ruleset (rotations, AWS, GCP, Slack, ...)
# rather than rolling our own detections.
useDefault = true
Original file line number Diff line number Diff line change
Expand Up @@ -89,6 +89,8 @@
"bender.yml",
"sync_develop_to_main.yml",
"pre_commit.yml",
"security_scan_pr.yml",
"security_scan_weekly.yml",
}
)

Expand Down
15 changes: 15 additions & 0 deletions trivy.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
# Copyright Advanced Micro Devices, Inc.
# SPDX-License-Identifier: MIT
#
# trivy configuration for Quartz, picked up by the rocm-security-gh
# reusable scanner (.github/workflows/security_scan_pr.yml and
# security_scan_weekly.yml) in place of its own org-wide default.
# Reference: https://trivy.dev/latest/docs/references/configuration/config-file/

scan:
skip-dirs:
- .git
- .venv
- venv
- release-nightly
- prereleases
9 changes: 9 additions & 0 deletions zizmor.yml

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yaml vs yml?

Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
# Copyright Advanced Micro Devices, Inc.
# SPDX-License-Identifier: MIT
#
# zizmor configuration for Quartz, picked up by the rocm-security-gh
# reusable scanner (.github/workflows/security_scan_pr.yml and
# security_scan_weekly.yml) in place of its own org-wide default.
# Reference: https://docs.zizmor.sh/configuration/

rules: {}
Loading