We value the security of Open3DCalc. If you find a security vulnerability:
- Do not open a public issue β report via email or private channel
- Send an email to ils15@github.com with:
- Clear description of the problem
- Steps to reproduce
- Estimated impact
- Suggested fix (if any)
- β Acknowledgment within 48h
- π Updates every 7 days until resolution
- π Public credit to the reporter after fix (if desired)
- π¦ Patch release within 14 days for critical vulnerabilities
This project is a React front-end application that runs 100% in the browser. There is no backend, database, or custom server. Potential vulnerabilities include:
- XSS (Cross-Site Scripting)
- localStorage data leakage
- dependencies with known CVEs
- Always use the latest version of Open3DCalc
- Keep your browser updated
- Review permissions if using the installed PWA version