Please use GitHub's private reporting: the Report a vulnerability button under the repository's Security tab. Do not open a public issue for anything security-sensitive.
SindriCAD is a solo project. I read every report, and I aim to acknowledge within a few days. If a report is valid, the fix ships in the next rolling beta and the advisory is credited to you (unless you prefer otherwise).
SindriCAD ships as a rolling beta release with an in-app updater. Only the latest beta is supported; older installers are not patched.
In scope:
- the desktop app: Tauri shell (Rust), webview frontend (TypeScript), bundled Python geometry sidecar
- the localhost sidecar WebSocket (token-gated, bound to 127.0.0.1)
- the signed update pipeline (
betarelease artifacts andlatest.json) - document parsing:
.sindrifiles and imported STL/3MF/STEP/OBJ - the app's network calls to tinkeratlas.com (account, publish, bug reports) and to printers you configure on your own LAN
Issues in the tinkeratlas.com website itself can go through the same private channel; they reach the same person.
Out of scope: vulnerabilities that require an already-compromised machine, and reports from automated scanners without a plausible impact.