Security fixes are generally applied to the latest available version of Trim.
| Version | Supported |
|---|---|
| Latest release | Yes |
| Older releases | No |
| Development branches | Best effort |
Users should update to the latest release before reporting a possible vulnerability.
Please do not open a public GitHub issue for a suspected security vulnerability.
Use GitHub's private vulnerability reporting feature if it is enabled for this repository.
When reporting a vulnerability, include:
- A clear description of the problem
- The affected Trim version
- The affected operating system
- Steps required to reproduce it
- The possible security impact
- Screenshots, logs, or proof-of-concept information when appropriate
- Whether the vulnerability has been disclosed anywhere else
Please avoid accessing, modifying, or exposing data that does not belong to you while investigating a potential vulnerability.
Examples include:
- Execution of unintended commands or code
- Unsafe handling of downloaded or installed files
- Path traversal or unauthorized file access
- Exposure of sensitive local information
- A method of bypassing an intended security restriction
- A vulnerable dependency that can realistically affect Trim users
Ordinary crashes, installation failures, incorrect instructions, calibration problems, and user-interface defects should be submitted through the normal Bug Report form.
Valid reports will be investigated and prioritized based on severity, reproducibility, and likely user impact.
Please allow time to investigate and prepare a correction before publicly discussing an unresolved vulnerability. Credit may be given to reporters who act responsibly, unless they prefer to remain anonymous.
This policy covers the Trim application and its official release packages.
Third-party slicers, printer firmware, operating systems, and unrelated services are outside the project’s direct security scope. Reports involving Trim’s interaction with those systems are still welcome.