Security fixes are made against the latest source revision. Older firmware and release packages may not receive fixes.
Please use the repository's private security-advisory channel after it is enabled. If no private channel is available, contact the maintainer privately before creating a public Issue.
Do not publish any of the following in an Issue, discussion, screenshot, or diagnostic attachment:
- Wi-Fi names or passwords
- Bambu access or refresh tokens
- printer serial numbers or access codes
- pairing tokens or OTA passwords
- private IP inventories, Cloudflare tunnel tokens, or account identifiers
companion/data/,.env,secrets.yaml, or complete diagnostic exports
Include the affected version, reproduction steps, expected impact, and a minimal redacted log. The maintainer should acknowledge a valid report before disclosure timing is discussed.
- Keep the companion configuration console on loopback or a trusted LAN.
- Use a unique pairing token and an OTA password of at least eight characters.
- Do not expose the ESP HTTP interface directly to the public Internet.
- Treat firmware, bundled runtimes, and release archives as supply-chain artifacts; publish checksums for every release.