# Security Policy ## Reporting Security Issues We appreciate community efforts to improve the security and robustness of Filament. If you discover a potential security vulnerability, please report it by opening an **Issue** on GitHub: - **Report via GitHub Issues**: Open an issue describing the vulnerability in detail. - **Report Requirements**: - The exact code location (source file path and relevant line numbers). - A clear technical explanation of the vulnerability mechanism. - Standard step-by-step reproduction instructions or a clear explanation of how the issue can be triggered in realistic Filament usage scenarios. - **Triage & Timelines**: We make no guarantees regarding response times or fix timeframes. Security issues will be evaluated and prioritized according to our regular development roadmap and backlog. ## Policy on Security Pull Requests **Filament does not accept unsolicited security pull requests.** We regularly receive low-quality, automated, or AI-generated security pull requests proposing speculative or broken changes without understanding Filament's architecture. As a result: - **All unsolicited security pull requests will be closed systematically without review.** - This applies especially to automated vulnerability scanner outputs and AI-generated patches. - If you believe you have discovered a vulnerability, please file an **Issue** instead. If maintainers determine a fix is required, it will be designed and implemented directly by the project maintainers. ## Bug Bounties, Rewards, and Attribution - Filament is an open-source project and **does not participate in bug bounty programs or offer financial rewards**. - We do **not** provide CVE credits, CVE assignment assistance, or contributor attribution ("street cred") for unsolicited, automated, or AI-generated vulnerability submissions.