Skip to content

Add SECURITY.md and SECURITY-INSIGHTS.yml - #46

Open
moezdil wants to merge 2 commits into
mainfrom
feat/lfx-security-meta
Open

moezdil wants to merge 2 commits into
mainfrom
feat/lfx-security-meta

Conversation

@moezdil

@moezdil moezdil commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

/kind documentation

Add the security metadata and contributor docs for LFX Insights / OpenSSF Scorecard: SECURITY.md (policy), SECURITY-INSIGHTS.yml (with the amd-hami-core subproject) and CONTRIBUTING.md. Companion workflow PRs add Scorecard (#47), CodeQL (#49) and SHA-pinned actions with image attestation (#48).

Fixes #45

Add a security policy and OpenSSF Security Insights metadata, matching the
main HAMi repository, so LFX Insights and Scorecard can find the security
contact, reporting process and dependency posture.

Part of #45

Signed-off-by: mesutoezdil <mesudozdil@gmail.com>
@hami-robot

hami-robot Bot commented Sep 29, 2026

Copy link
Copy Markdown

@moezdil: The label(s) kind/documentation cannot be applied, because the repository doesn't have them.

Details

In response to this:

/kind documentation

Add a security policy and OpenSSF Security Insights metadata (the LFX security YAML), matching the main HAMi repo, so LFX Insights and OpenSSF Scorecard find the security contact, reporting process and dependency posture.

Part of #45

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 2769717b-4178-4790-bb76-0a85c780d9da


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hami-robot

hami-robot Bot commented Sep 29, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: moezdil

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@moezdil moezdil self-assigned this Sep 29, 2026
Add a contribution guide (build, issue and pull request workflow, DCO) so new
contributors have clear guidance, and list the amd-hami-core subproject in the
security insights repositories. Addresses OSPS-GV-03.01 and OSPS-QA-04.01.

Part of #45

Signed-off-by: mesutoezdil <mesudozdil@gmail.com>
@moezdil moezdil added the kind/documentation Categorizes issue or PR as related to documentation. label Sep 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

kind/documentation Categorizes issue or PR as related to documentation.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

LFX Insights / OpenSSF Scorecard security hardening

1 participant