This policy covers every repository in the HoffmanEngineering organization, including the 3D Print Log web app, API, mobile shell, and the Cura and Slic3r plugins.
If you discover a security vulnerability, please do not open a public GitHub issue.
Instead, email hello@3dprintlog.com with:
- a description of the issue,
- the repository and version affected,
- steps to reproduce, and
- the impact you believe it has.
We will respond as quickly as possible and coordinate a fix before any public disclosure. If you would like credit for the report, say so and we will name you in the release notes.
The slicer plugins run locally on a user's machine and send print data to the 3D Print Log API using a personal API key. Reports involving that key — how it is stored, transmitted, or scoped — are in scope and worth sending.
Findings against the production site itself (https://www.3dprintlog.com) are also in scope. Please do not run automated scanners against it; it is a small hosted service and load-generating tests are indistinguishable from an attack.