Skip to content

Security: ZackaryShen/ColorYourModel

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

Please do not open a public GitHub issue for security problems.

Use GitHub's private vulnerability reporting instead: Security tab → Report a vulnerability, or https://github.com/ZackaryShen/ColorYourModel/security/advisories/new.

Include, where possible:

  • steps to reproduce (model files, exports, or crafted inputs involved)
  • affected version / commit
  • impact assessment

We aim to respond within 7 days. Coordinated disclosure is preferred; credit is given unless you ask to remain anonymous.

Scope

ColorYourModel is an offline desktop application: it parses STL/3MF/OBJ files locally and writes export files. Reports about malicious model files crashing the parser or causing resource exhaustion are in scope.

There aren't any published security advisories