Skip to content

Add tflite-micro fuzzing project#15328

Open
theteatoast wants to merge 3 commits intogoogle:masterfrom
theteatoast:add-tflite-micro
Open

Add tflite-micro fuzzing project#15328
theteatoast wants to merge 3 commits intogoogle:masterfrom
theteatoast:add-tflite-micro

Conversation

@theteatoast
Copy link
Copy Markdown

@theteatoast theteatoast commented Apr 10, 2026

Project is considered as OT1 asset by Google OSS VRP Repository Tiers

@google-cla
Copy link
Copy Markdown

google-cla bot commented Apr 10, 2026

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

@github-actions
Copy link
Copy Markdown

theteatoast is integrating a new project:
- Main repo: https://github.com/tensorflow/tflite-micro
- Criticality score: 0.48436

Copy link
Copy Markdown
Collaborator

@DavidKorczynski DavidKorczynski left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

can you please coordinate with maintainers e.g. ideally landing the harness in the target repository and make sure they have emails in the project.yaml to receive notifications, and no need to list potential vulnerabilities in the PR description -- please also send those to the maintainers privately.

@theteatoast
Copy link
Copy Markdown
Author

theteatoast commented Apr 10, 2026

Sorry for the confusion, I may have misunderstood the Google VRP rules. I'll update and clean up the PR messages accordingly, remove any vulnerability details, and follow the proper process going forward. Thanks for guiding.

@DavidKorczynski
Copy link
Copy Markdown
Collaborator

All good! Thanks

- Add OSS-Fuzz integration
- Configure build and fuzz targets
- Add initial seed corpus
- Register Gather-related ops
- Add seed corpus for Gather models
- Extend fuzzing dictionary
- Add seed generation script
@theteatoast
Copy link
Copy Markdown
Author

theteatoast commented Apr 11, 2026

Hello @DavidKorczynski

As tflite-micro is considered an OT1 asset by google, I submitted the vulns through OSS VRP.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants