diff --git a/.github/workflows/pr.yaml b/.github/workflows/pr.yaml index b4582957ee..2d2ee367aa 100644 --- a/.github/workflows/pr.yaml +++ b/.github/workflows/pr.yaml @@ -100,6 +100,7 @@ jobs: - '!.github/workflows/check-c-abi.yaml' - '!.github/workflows/labeler.yml' - '!.github/workflows/publish-rust.yaml' + - '!.github/workflows/security-suite.yml' - '!.github/workflows/store-c-abi-baseline.yaml' - '!.github/workflows/test.yaml' - '!.github/workflows/trigger-breaking-change-alert.yaml' @@ -132,6 +133,7 @@ jobs: - '!.github/workflows/check-c-abi.yaml' - '!.github/workflows/labeler.yml' - '!.github/workflows/publish-rust.yaml' + - '!.github/workflows/security-suite.yml' - '!.github/workflows/store-c-abi-baseline.yaml' - '!.github/workflows/test.yaml' - '!.github/workflows/trigger-breaking-change-alert.yaml' @@ -177,6 +179,7 @@ jobs: - '!.github/workflows/check-c-abi.yaml' - '!.github/workflows/labeler.yml' - '!.github/workflows/publish-rust.yaml' + - '!.github/workflows/security-suite.yml' - '!.github/workflows/store-c-abi-baseline.yaml' - '!.github/workflows/test.yaml' - '!.github/workflows/trigger-breaking-change-alert.yaml' @@ -229,6 +232,7 @@ jobs: - '!.github/workflows/check-c-abi.yaml' - '!.github/workflows/labeler.yml' - '!.github/workflows/publish-rust.yaml' + - '!.github/workflows/security-suite.yml' - '!.github/workflows/store-c-abi-baseline.yaml' - '!.github/workflows/test.yaml' - '!.github/workflows/trigger-breaking-change-alert.yaml' @@ -278,6 +282,7 @@ jobs: - '!.github/workflows/check-c-abi.yaml' - '!.github/workflows/labeler.yml' - '!.github/workflows/publish-rust.yaml' + - '!.github/workflows/security-suite.yml' - '!.github/workflows/store-c-abi-baseline.yaml' - '!.github/workflows/test.yaml' - '!.github/workflows/trigger-breaking-change-alert.yaml' @@ -332,6 +337,7 @@ jobs: - '!.github/workflows/check-c-abi.yaml' - '!.github/workflows/labeler.yml' - '!.github/workflows/publish-rust.yaml' + - '!.github/workflows/security-suite.yml' - '!.github/workflows/store-c-abi-baseline.yaml' - '!.github/workflows/test.yaml' - '!.github/workflows/trigger-breaking-change-alert.yaml' @@ -381,6 +387,7 @@ jobs: - '!.github/workflows/check-c-abi.yaml' - '!.github/workflows/labeler.yml' - '!.github/workflows/publish-rust.yaml' + - '!.github/workflows/security-suite.yml' - '!.github/workflows/store-c-abi-baseline.yaml' - '!.github/workflows/test.yaml' - '!.github/workflows/trigger-breaking-change-alert.yaml' diff --git a/.github/workflows/security-suite.yml b/.github/workflows/security-suite.yml new file mode 100644 index 0000000000..52517d3c3a --- /dev/null +++ b/.github/workflows/security-suite.yml @@ -0,0 +1,42 @@ +# SPDX-FileCopyrightText: Copyright (c) 2026, NVIDIA CORPORATION & AFFILIATES. All rights reserved. +# SPDX-License-Identifier: Apache-2.0 + +name: security suite + +on: + push: + branches: + - "main" + - "release/*" + - "pull-request/[0-9]+" + workflow_dispatch: + +concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: true + +permissions: {} + +jobs: + security-suite: + # Pulse needs nv-gha-runners + Vault/nvcr vars; skip on forks. + if: github.repository == 'NVIDIA/cuvs' + # The caller must grant every permission the reusable workflow declares, including + # scans this repo does not enable — GitHub validates the grant before evaluating + # each scan's condition. + permissions: + actions: read + contents: read + id-token: write # OIDC -> Vault -> nvcr.io image pull + security-events: write # publish redacted SARIF to code scanning + uses: NVIDIA/security-workflows/.github/workflows/security-suite.yml@711025b090f2aa728da576700750b195d1e816dc # v0.3.0 + with: + enable-secret-scan: true + enable-sast-scan: true + secret-runs-on: linux-amd64-cpu4 + # Set the policy explicitly so enforcement can't drift with upstream defaults. + # unverified — fail on verified/live secrets; warn on unverified [default] + # strict — fail on any finding (verified or unverified) + # all — warn only; never fail the job on findings + secret-failure-policy: unverified + sast-languages: '["actions","java-kotlin","python","rust"]' diff --git a/.pre-commit-config.yaml b/.pre-commit-config.yaml index 0f1d6b7842..7a8c564c94 100644 --- a/.pre-commit-config.yaml +++ b/.pre-commit-config.yaml @@ -2,6 +2,11 @@ # SPDX-License-Identifier: Apache-2.0 repos: + # Runs first so a leaked credential blocks the commit before any formatter runs. + - repo: https://github.com/NVIDIA/security-workflows + rev: v0.3.0 + hooks: + - id: secret-scan-trufflehog - repo: https://github.com/pre-commit/pre-commit-hooks rev: v6.0.0 hooks: