From 9a739b9fc7db36f5eee18a2466e2894b42bfcd03 Mon Sep 17 00:00:00 2001 From: gmanal Date: Tue, 11 Aug 2026 19:01:08 +0530 Subject: [PATCH] Enable security scanning via NVIDIA/security-workflows suite Call the centrally maintained security suite rather than wiring each scan separately: one pinned reference runs the Pulse secret scan and CodeQL SAST. Every scan in the suite is opt-in, so scanners added upstream later do not switch themselves on here. SAST analyzes python and actions. Both need no toolchain (build-mode none), so they add no build cost and no dependency on the CUDA/conda toolchain. actions matters here because labeler.yml and trigger-breaking-change-alert.yaml run on pull_request_target. c-cpp, java-kotlin, rust and go all need a working build to produce a database and are left out deliberately. Add the secret-scan-trufflehog pre-commit hook as the local advisory layer; the Pulse scan is the server-side enforcement layer. --- .github/workflows/security-suite.yml | 46 ++++++++++++++++++++++++++++ .pre-commit-config.yaml | 7 +++++ 2 files changed, 53 insertions(+) create mode 100644 .github/workflows/security-suite.yml diff --git a/.github/workflows/security-suite.yml b/.github/workflows/security-suite.yml new file mode 100644 index 0000000000..494ff46c54 --- /dev/null +++ b/.github/workflows/security-suite.yml @@ -0,0 +1,46 @@ +# SPDX-FileCopyrightText: Copyright (c) 2026, NVIDIA CORPORATION & AFFILIATES. All rights reserved. +# SPDX-License-Identifier: Apache-2.0 +# +# CI security scanning via the NVIDIA/security-workflows suite: Pulse secret scan + CodeQL SAST. +# Pulse runs on Linux nv-gha-runners. +# Pinned to security-workflows v0.3.0. + +name: security suite + +on: + push: + branches: + - "main" + - "release/*" + - "pull-request/[0-9]+" + workflow_dispatch: + +concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: true + +permissions: {} + +jobs: + security-suite: + # Pulse needs nv-gha-runners + Vault/nvcr vars; skip on forks. + if: github.repository == 'NVIDIA/cuvs' + # The caller must grant every permission the reusable workflow declares, including + # scans this repo does not enable — GitHub validates the grant before evaluating + # each scan's condition. + permissions: + actions: read + contents: read + id-token: write # OIDC -> Vault -> nvcr.io image pull + security-events: write # publish redacted SARIF to code scanning + uses: NVIDIA/security-workflows/.github/workflows/security-suite.yml@711025b090f2aa728da576700750b195d1e816dc # v0.3.0 + with: + enable-secret-scan: true + enable-sast-scan: true + secret-runs-on: linux-amd64-cpu4 + # Set the policy explicitly so enforcement can't drift with upstream defaults. + # unverified — fail on verified/live secrets; warn on unverified [default] + # strict — fail on any finding (verified or unverified) + # all — warn only; never fail the job on findings + secret-failure-policy: unverified + sast-languages: '["python","actions"]' diff --git a/.pre-commit-config.yaml b/.pre-commit-config.yaml index 0f1d6b7842..a7248aafb4 100644 --- a/.pre-commit-config.yaml +++ b/.pre-commit-config.yaml @@ -2,6 +2,13 @@ # SPDX-License-Identifier: Apache-2.0 repos: + # Runs first so a leaked credential blocks the commit before any formatter runs. + # Self-installing: pre-commit downloads a pinned, checksum-verified trufflehog into + # the hook environment on first use. CI enforces the same class of finding via Pulse. + - repo: https://github.com/NVIDIA/security-workflows + rev: v0.3.0 + hooks: + - id: secret-scan-trufflehog - repo: https://github.com/pre-commit/pre-commit-hooks rev: v6.0.0 hooks: