Conversation
Copies standardised security scanning config from ROCm/rocm-repo-template.
|
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
Security Scanning Workflows Enablement
This PR adds standardized security scanning workflows and configurations from
ROCm/rocm-repo-template.Security Controls
Files added / updated
.github/workflows/pr-security-scan.yml— scans every pull request.github/workflows/weekly-security-scan.yml— scheduled weekly scan.github/dependabot.yml— automated dependency updates.github/scan_tools_configs/bandit.yml— Python static analysis config.github/scan_tools_configs/gitleaks.toml— secret detection config.github/scan_tools_configs/trivy.yml— container/dependency vulnerability config.github/scan_tools_configs/zizmor.yml— GitHub Actions security configWhy
This change aligns this repository with the ROCm GitHub Organization Security Baseline and enables consistent security controls across ROCm repositories.
For more details, refer ROCm GitHub Org Security Controls Baseline Architecture
Support/Questions: Teams Channel ROCm Security Discussions