Conversation
Add a security policy and OpenSSF Security Insights metadata, matching the main HAMi repository, so LFX Insights and Scorecard can find the security contact, reporting process and dependency posture. Part of #45 Signed-off-by: mesutoezdil <mesudozdil@gmail.com>
|
@moezdil: The label(s) DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: moezdil The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
Add a contribution guide (build, issue and pull request workflow, DCO) so new contributors have clear guidance, and list the amd-hami-core subproject in the security insights repositories. Addresses OSPS-GV-03.01 and OSPS-QA-04.01. Part of #45 Signed-off-by: mesutoezdil <mesudozdil@gmail.com>
/kind documentation
Add the security metadata and contributor docs for LFX Insights / OpenSSF Scorecard: SECURITY.md (policy), SECURITY-INSIGHTS.yml (with the amd-hami-core subproject) and CONTRIBUTING.md. Companion workflow PRs add Scorecard (#47), CodeQL (#49) and SHA-pinned actions with image attestation (#48).
Fixes #45