TME Studio employs several automated tools to continuously monitor and improve security:
a. GitHub Dependabot: Detects vulnerabilities in dependencies (including transitive) and creates security update PRs. Dependabot alerts published.
b. Renovate: Automates version updates for direct dependencies and maintains lock file freshness to keep transitive dependencies current. Dependency Dashboard published.
c. trivy: Pre commit to GitHub scans Python dependencies for known vulnerabilities using data from GitHub Advisory Database and OSV.dev. vulnerabilities.json published per release.
a. trivy (license scanning): Inspects and matches the licenses of all dependencies with an allow list to ensure compliance with licensing requirements and avoid using components with problematic licenses. licenses.json published per release.
b. trivy (CycloneDX SBOM): Generates Software Bill of Materials in CycloneDX format including per-component license and vulnerability data. sbom.json published per release.
c. trivy (SPDX SBOM): Generates Software Bill of Materials in SPDX format from the full dependency lock file including dev deps. sbom.spdx published per release.
a. SonarQube: Performs comprehensive static code analysis to detect code quality issues, security vulnerabilities, and bugs. Security hotspots published.
a. GitHub Secret scanning: Automatically scans for secrets in the codebase and alerts if any are found. Secret scanning alerts published. b. Yelp/detect-secrets: Pre-commit hook and automated scanning to prevent accidental inclusion of secrets or sensitive information in commits. Pre-Commit hook published.
We follow these security best practices:
- Regular dependency updates
- Comprehensive test coverage
- Code review process for changes by external contributors
- Automated CI/CD pipelines including security checks
- Adherence to Python security best practices
We promote security awareness among contributors and users:
- We indicate security as a priority in our code style guide, to be followed by human and agentic contributors as mandatory
- We publish our security posture in SECURITY.md (this document), encouraging users to report vulnerabilities.
For questions about security compliance or for more details about our security practices, please contact info@aignostics.com.