Note well that in the default config, syncthing grants remote code execution on your machine to the syncthing developers in the form of Solarwinds-style no interaction autoupdate.
A compromise of the centralized release process could steal all of your (and everyone else's!) files by updating to a malicious version automatically with zero interaction.
Set the syncthing binary's file ownership as root and run it as a normal user so it can't get overwritten, and set STNOUPGRADE=1 in the environment to disable this dangerous default behavior.