Please do not open public issues.
Preferred: use GitHub Private Vulnerability Reporting (Settings → Code security → Private vulnerability reporting → Enable). If enabled, submit via “Report a vulnerability” in the repo Security tab.
Alternative: use the AMD Product Security portal: https://www.amd.com/en/resources/product-security.html
When reporting, include:
- Description and impact
- Steps to reproduce or proof of concept
- Affected versions or commit hashes
- Relevant logs or environment details (if available)
We aim to acknowledge reports within 1 business day.
This policy covers code and configuration in this repository. If the issue is in third-party dependencies, please report upstream; for AMD products unrelated to this repo, use the AMD Product Security portal.