Skip to content

Security: espentruls/Trim

Security

.github/SECURITY.md

Security Policy

Supported versions

Security fixes are generally applied to the latest available version of Trim.

Version Supported
Latest release Yes
Older releases No
Development branches Best effort

Users should update to the latest release before reporting a possible vulnerability.

Reporting a vulnerability

Please do not open a public GitHub issue for a suspected security vulnerability.

Use GitHub's private vulnerability reporting feature if it is enabled for this repository.

When reporting a vulnerability, include:

  • A clear description of the problem
  • The affected Trim version
  • The affected operating system
  • Steps required to reproduce it
  • The possible security impact
  • Screenshots, logs, or proof-of-concept information when appropriate
  • Whether the vulnerability has been disclosed anywhere else

Please avoid accessing, modifying, or exposing data that does not belong to you while investigating a potential vulnerability.

What qualifies as a security report?

Examples include:

  • Execution of unintended commands or code
  • Unsafe handling of downloaded or installed files
  • Path traversal or unauthorized file access
  • Exposure of sensitive local information
  • A method of bypassing an intended security restriction
  • A vulnerable dependency that can realistically affect Trim users

Ordinary crashes, installation failures, incorrect instructions, calibration problems, and user-interface defects should be submitted through the normal Bug Report form.

Response process

Valid reports will be investigated and prioritized based on severity, reproducibility, and likely user impact.

Please allow time to investigate and prepare a correction before publicly discussing an unresolved vulnerability. Credit may be given to reporters who act responsibly, unless they prefer to remain anonymous.

Scope

This policy covers the Trim application and its official release packages.

Third-party slicers, printer firmware, operating systems, and unrelated services are outside the project’s direct security scope. Reports involving Trim’s interaction with those systems are still welcome.

There aren't any published security advisories