diff --git a/.github/CODEOWNERS b/.github/CODEOWNERS new file mode 100644 index 00000000..ded88d24 --- /dev/null +++ b/.github/CODEOWNERS @@ -0,0 +1,6 @@ +# >>> runpod secret gate (deploy-secret-gate.sh) >>> +# Owners of the secret gate's files. +# CODEOWNERS is last-match-wins: keep this block at the end of the file. +/.github/workflows/pr-security-scan.yml @runpod/security +/.github/workflows/pr-ai-review.yml @runpod/security +# <<< runpod secret gate (deploy-secret-gate.sh) <<< diff --git a/.github/workflows/pr-ai-review.yml b/.github/workflows/pr-ai-review.yml new file mode 100644 index 00000000..858a48bb --- /dev/null +++ b/.github/workflows/pr-ai-review.yml @@ -0,0 +1,23 @@ +# Stage 2 of the secret gate. The jobs live in runpod/secret_detector; see its README. +# Written by deploy-secret-gate.sh. +name: PR AI Security Review + +on: + workflow_run: + workflows: ["PR Security Scan"] + types: [completed] + +permissions: + contents: read + +jobs: + review: + uses: runpod/secret_detector/.github/workflows/pr-ai-review.yml@main + permissions: + contents: read + pull-requests: write + statuses: write + with: + review-contacts: "runpod/security" + secrets: + LITELLM_API_KEY: ${{ secrets.LITELLM_API_KEY }} diff --git a/.github/workflows/pr-security-scan.yml b/.github/workflows/pr-security-scan.yml new file mode 100644 index 00000000..299b5e4a --- /dev/null +++ b/.github/workflows/pr-security-scan.yml @@ -0,0 +1,14 @@ +# Stage 1 of the secret gate. The job lives in runpod/secret_detector; see its README. +# Written by deploy-secret-gate.sh. +name: PR Security Scan + +on: + pull_request: + types: [opened, synchronize, reopened, ready_for_review] + +permissions: + contents: read + +jobs: + scan: + uses: runpod/secret_detector/.github/workflows/pr-security-scan.yml@main