Skip to content

Security: google/filament

SECURITY.md

Security Policy

Reporting Security Issues

We appreciate community efforts to improve the security and robustness of Filament. If you discover a potential security vulnerability, please report it by opening an Issue on GitHub:

  • Report via GitHub Issues: Open an issue describing the vulnerability in detail.
  • Report Requirements:
    • The exact code location (source file path and relevant line numbers).
    • A clear technical explanation of the vulnerability mechanism.
    • Standard step-by-step reproduction instructions or a clear explanation of how the issue can be triggered in realistic Filament usage scenarios.
  • Triage & Timelines: We make no guarantees regarding response times or fix timeframes. Security issues will be evaluated and prioritized according to our regular development roadmap and backlog.

Policy on Security Pull Requests

Filament does not accept unsolicited security pull requests.

We regularly receive low-quality, automated, or AI-generated security pull requests proposing speculative or broken changes without understanding Filament's architecture. As a result:

  • All unsolicited security pull requests will be closed systematically without review.
  • This applies especially to automated vulnerability scanner outputs and AI-generated patches.
  • If you believe you have discovered a vulnerability, please file an Issue instead. If maintainers determine a fix is required, it will be designed and implemented directly by the project maintainers.

Bug Bounties, Rewards, and Attribution

  • Filament is an open-source project and does not participate in bug bounty programs or offer financial rewards.
  • We do not provide CVE credits, CVE assignment assistance, or contributor attribution ("street cred") for unsolicited, automated, or AI-generated vulnerability submissions.

There aren't any published security advisories