Project / Source code

The whole thing is on GitHub

KalderaShield is Apache-2.0 licensed open source: the desktop app, the Android app, the browser extension, the native messaging host and this site. Every security claim on this website can be traced to code or to a test that runs in public CI.

What the codebase is

Four projects, one repository

The desktop application pairs a React and TypeScript front end with a Rust core through Tauri 2: the UI renders in the system WebView, the native side handles the updater, the extension bridge and platform integrations. Vault persistence runs on wa-sqlite with a versioned schema envelope.

The browser extension is a Manifest V3 TypeScript build for Chromium and Firefox, and the Android app is a Tauri Android project with AndroidKeyStore biometric binding. The native messaging host and the IPC bridge live in the Rust workspace, where the pairing token, lease and frame-encryption logic are easiest to audit.

The site itself is plain committed HTML — no build step for deployment — with generator scripts and quality gates checked in next to the pages they produce.

The gates every change passes

Typecheck and 2204 unit tests

248 test files with enforced coverage thresholds: 90% lines, 90% statements, 85% functions, 80% branches. A regression below the threshold fails the build, not a dashboard.

Fuzz, mutation and security gates

fast-check property tests hammer importer, backup and attachment paths with malformed input. Stryker mutation testing grades test quality. Dedicated gates check CSP hardening, release artifacts, debug markers and secrets.

Supply-chain analysis in CI

CodeQL analyzes the code, OpenSSF Scorecard grades the repository posture, gitleaks blocks committed secrets, and the dependency policy fails on any high or critical advisory with documented acceptance for the rest.

Security Architecture

What open source here means — and does not

A claim with its boundary

Open source lets anyone read the code; it does not by itself prove that anyone has. Reading is the whole point: the threat model, the acceptance registers and the audit scope are in the repository so reviewers start from the same map. An independent audit has not been completed — the audit status page says so directly.

TypeScript

Front end and extension

React UI, extension and shared vault logic, strictly typed; no React inline styles, enforced by the CSP gate.

Rust

Native core

Tauri 2 commands, native messaging host, loopback IPC bridge and updater plumbing; cargo fmt and focused atomic-write tests gate every release.

Apache-2.0

License

The whole project plus a THIRD-PARTY license file for bundled components. No proprietary blobs in the installers.

Frequently Asked Questions

Contributing and reporting

How do I report a security vulnerability?

Privately, never as a public issue: GitHub private vulnerability reporting or the email in SECURITY.md. Acknowledgement within 48 hours, triage within 7 days, coordinated disclosure within 90.

Can I contribute code?

Yes — through GitHub pull requests. The gates described above run on every change, so the fastest way to help is a change that keeps them green and includes its own tests.

Can I build the installers myself?

Yes. The local release guide documents the exact commands per platform, and the release script collects artifacts with SHA-256 checksums into release-local/<platform>/.

Related pages

Download Installer