Skip to content

chore: add security scanning workflows - #2466

Open
haribabug wants to merge 1 commit into
developfrom
add-security-scanning
Open

haribabug wants to merge 1 commit into
developfrom
add-security-scanning

Conversation

@haribabug

Copy link
Copy Markdown

Security Scanning Workflows Enablement

This PR adds standardized security scanning workflows and configurations from ROCm/rocm-repo-template.

Security Controls

  • PR Security Scan
  • Weekly Security Scan
  • Dependabot
  • CodeQL, Bandit, Gitleaks, Trivy, and Zizmor

Files added / updated

  • .github/workflows/pr-security-scan.yml — scans every pull request
  • .github/workflows/weekly-security-scan.yml — scheduled weekly scan
  • .github/dependabot.yml — automated dependency updates
  • .github/scan_tools_configs/bandit.yml — Python static analysis config
  • .github/scan_tools_configs/gitleaks.toml — secret detection config
  • .github/scan_tools_configs/trivy.yml — container/dependency vulnerability config
  • .github/scan_tools_configs/zizmor.yml — GitHub Actions security config

Why

This change aligns this repository with the ROCm GitHub Organization Security Baseline and enables consistent security controls across ROCm repositories.


For more details, refer ROCm GitHub Org Security Controls Baseline Architecture

Support/Questions: Teams Channel ROCm Security Discussions

Copies standardised security scanning config from
ROCm/rocm-repo-template.
@haribabug
haribabug requested a review from causten as a code owner September 29, 2026 20:51
@rocmlir-pr-reviewer rocmlir-pr-reviewer Bot added the modifies-ci-paths PR modifies the Claude review CI security perimeter; audit before applying claude-review label Sep 29, 2026
@rocmlir-pr-reviewer

Copy link
Copy Markdown

⚠️ This PR modifies the Claude-review CI security perimeter

The following files in this PR control whether and how the
claude-review workflow protects its LLM Gateway secrets at
runtime (see .github/workflows/CLAUDE_AUTO_REVIEW.md):

  • .github/workflows/pr-security-scan.yml
  • .github/workflows/weekly-security-scan.yml

Before applying the claude-review label on this PR, please:

  1. Audit the diff in these paths line-by-line. A malicious or
    accidental change could disable the --allowedTools
    restriction, the overlay step, the sanitizer, or the
    review/post job split -- any of which would expose the
    secrets in env to the PR-modified workflow.
  2. If the changes are legitimate and you want a Claude review,
    do NOT apply the claude-review label. Instead, run via
    Actions → Claude Auto Review → Run workflow and enter
    this PR's number. The dispatch path runs from the trusted,
    code-owner-approved version of the workflow on
    develop, so a malicious PR-side
    modification cannot affect the run.

(This banner is automated. The modifies-ci-paths label
will be removed automatically if a future push removes the
perimeter modifications. The Layer-3 in-workflow guard will
additionally fail the claude-review label-triggered run
on this PR if the label is applied while perimeter changes
are present.)

@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

modifies-ci-paths PR modifies the Claude review CI security perimeter; audit before applying claude-review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants