Please do not open a public issue for security problems. Report them privately through GitHub's private vulnerability reporting (Security tab > Report a vulnerability). You will get an answer as soon as possible; please allow time for a fix before disclosing details.
SwPy runs Python inside SOLIDWORKS, with the permissions of the logged-in Windows user. That is its purpose, so keep these points in mind:
- Running a script means running code. A script can do anything the user can: read and write files, start programs, use the network, change models. Only run scripts you trust - exactly like VBA macros.
- Script folder and startup scripts. Every
.pyin the script folder becomes a button, and scripts instartup\run automatically when SOLIDWORKS starts. If you pointScriptsFolderat a shared or network folder, everyone who can write to it can run code on every machine that uses it: restrict write access. # r:package headers install packages from PyPI into%LOCALAPPDATA%\SwPy\site-packageswhen a script runs. Only plain package names and version specifiers are accepted (no pip options, URLs or paths), but a package is still third-party code: pin versions you trust (# r: openpyxl==3.1.5).- Automation interface. Other programs of the same Windows user on the same machine can run code
through
ISldWorks.GetAddInObject("SwPy.AddIn").Execute(...)(that is howswpy.client, Excel and C# integration work). SwPy opens no network port and accepts no remote connections. - Event handlers run inside SOLIDWORKS operations; they are isolated from errors but not from malicious code - the same rule as for scripts applies.
- No elevation. SwPy installs per user without admin rights. The optional
install.ps1 -Machinewrites one SOLIDWORKS add-in registry key under HKLM and nothing else.
- The bundled Python runtime and pip wheel are downloaded by
tools/fetch_python.ps1with pinned versions and SHA-256 verification. - The add-in depends on
pythonnetandScintilla5.NET(NuGet, pinned inSwPy.AddIn.csproj) and on the SOLIDWORKS interop assemblies of the local installation. - The repository contains no credentials. SOLIDWORKS Document Manager licence keys and PDM credentials belong in your own scripts or environment, never in this repository.