Skip to content

Security: AkashVarma007/pcb-playground

Security

SECURITY.md

Security & Safety Policy

This repository is a hardware design plus local code generators. It has no server, no network calls, and handles no user credentials, so the usual software-vulnerability surface is small — but it describes mains-connected equipment, where a design defect can be physically dangerous. This policy covers both.

Threat model (be honest about what matters here)

  • Software surface: the tools in tools/ are pure-Python generators that read design.py and write KiCad files locally. The only third-party dependency is kiutils (pinned in requirements.txt). There is no code execution on untrusted input and nothing is fetched at runtime. Realistic software risk: a supply-chain issue in a dependency.
  • The real risk is physical. This is a non-earth-referenced off-line SMPS: the entire primary side sits at lethal mains potential. A safety-critical defect — for example a primary↔secondary gap below 6 mm, a wrong mains-side footprint, a missing/incorrect fuse or bleeder, or a broken isolation DRC rule — is the highest-severity issue this project can have.

Reporting a vulnerability or a safety defect

Please report privately first — do not open a public issue for a safety-critical isolation or mains defect until it has been fixed.

  • Email: g.akashvarma@gmail.com with a clear description and, if possible, the affected part reference, net, or the validate.py output.
  • Expect an acknowledgement within a reasonable time; fixes to safety defects are prioritised.
  • Dependency / tooling vulnerabilities can also be reported the same way, or via GitHub's private security advisories if enabled.

Supported versions

This is an actively developed single design; fixes land on main. There is no back-port branch. Always build from the latest main and re-run ./build.sh so the 6 mm isolation check and the full netlist validation run against your copy.

Scope

  • ✅ In scope: incorrect isolation/creepage, wrong mains-side parts or footprints, missing protection (fuse/MOV/bleeder), a validator that passes something it shouldn't, dependency issues.
  • ❌ Out of scope: the inherent danger of building mains hardware (that is documented, not a bug), and use of the design without the required ERC/DRC/bench verification described in the README.

There aren't any published security advisories