Skip to content

Security: kc-ml2/tt-system-firmware

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in this project, please report it responsibly using GitHub's private vulnerability reporting feature.

Do not report security vulnerabilities through public GitHub issues.

How to Report

  1. Navigate to the Security tab of this repository
  2. Click "Report a vulnerability"
  3. Provide a detailed description of the vulnerability, including:
    • Steps to reproduce the issue
    • Potential impact
    • Any suggested fixes (if applicable)

For detailed instructions on privately reporting a security vulnerability, see GitHub's documentation.

Questions or Discussion

If you have questions about the vulnerability or need to start a conversation about it, please contact ospo@tenstorrent.com directly.

Our Security Process

  1. Report: Submit a vulnerability report through GitHub's Security tab
  2. Acknowledgment: Tenstorrent will respond within 2 business days
  3. Triage: Our team will assess the issue and update its priority and risk level
  4. Fix Development: A fix will be developed in a private branch, with reporter feedback when possible
  5. Disclosure: A security advisory will be published once the fix is patched and merged to the main branch

Thank you for helping keep this project and our users safe!

There aren't any published security advisories