Skip to content

Security: HoffmanEngineering/.github

Security

SECURITY.md

Security Policy

This policy covers every repository in the HoffmanEngineering organization, including the 3D Print Log web app, API, mobile shell, and the Cura and Slic3r plugins.

Reporting a vulnerability

If you discover a security vulnerability, please do not open a public GitHub issue.

Instead, email hello@3dprintlog.com with:

  • a description of the issue,
  • the repository and version affected,
  • steps to reproduce, and
  • the impact you believe it has.

We will respond as quickly as possible and coordinate a fix before any public disclosure. If you would like credit for the report, say so and we will name you in the release notes.

Scope

The slicer plugins run locally on a user's machine and send print data to the 3D Print Log API using a personal API key. Reports involving that key — how it is stored, transmitted, or scoped — are in scope and worth sending.

Findings against the production site itself (https://www.3dprintlog.com) are also in scope. Please do not run automated scanners against it; it is a small hosted service and load-generating tests are indistinguishable from an attack.

There aren't any published security advisories