__CAPGO_KEEP_0__ | セキュリティポリシー

Security Policy

Contact: https://github.com/Cap-go/capgo/security/advisories/new
Canonical: https://capgo.app/security.txt

Capgoでは、システムのセキュリティを最優先とします。ただし、システムのセキュリティに尽力しても、必ずしも脆弱性が存在しないとは限りません。

脆弱性が発見された場合、できるだけ早く対処することができるように、ご協力いただけるようお願いいたします。

お客様やシステムをよりよく保護するために、お手伝いください。

  • 脆弱性の範囲外:
  • ページに敏感なアクションがない場合のクリックジャッキング攻撃。
  • ログアウト/ログイン CSRF (未認証)。
  • ユーザーのデバイスに物理的にアクセスすることや、MITM攻撃を必要とする攻撃。
  • サービス中断 (DoS) による活動
  • HTML/CSS を変更できないため、コンテンツの偽装やテキストの挿入に関する問題
  • メールの偽装
  • DNSSEC、CAA、CSP ヘッダーが欠落している
  • 非機密性の cookie に対して Secure または HTTP only フラグが欠落している
  • 死リンク
  • ユーザー情報の抽出
  • SSRF or DNS spoofing reports against webhooks or website preview. These features run on serverless infrastructure and cannot be used to reach private Capgo infrastructure, so they are not exploitable in our environment.
  • User-owned application code or project configuration that Capgo does not own, ship, or control, including files such as capacitor.config.ts, config.capacitor.ts, app source code, and environment-specific settings.
  • Access to Capgo bundle files or proof that bundle files can be downloaded. Bundle files are public web assets, users are informed of this, and access to them is not considered a data breach.

Supabase Auth の既知の制限

一部の発見は、Supabase Auth の動作に関連しているが、再度報告されます。これらの問題は、Supabase のデモプロジェクトに似た設定で再現できる場合、または Supabase の構成変更が Capgo のセキュリティ規則を変更せずに問題を修正する場合にのみ、Supabase 側の問題として扱われます。修正が Capgo 所有の SQL、RPC、RLS ポリシー、関数、またはアプリロジックを変更する場合、それは Capgo の問題であり、報告する必要があります。

  • Reports must include a reproducible demo Supabase project, with steps, that matches our settings and demonstrates the behavior.
  • Reports must include the exact fix path: either the Supabase setting/config change that resolves the behavior, or the Capgo-owned code/config object that must change.
  • Account/email flows are validated against the Supabase project settings (for example, whether email verification is disabled and capture flow is used).
  • Password and email/password update flows may depend on current Supabase Auth session and re-verification settings.
  • If a demo project proves a concrete Supabase-side fix with no Capgo policy change, or shows a concrete Capgo-owned defect, we review it as actionable.

Testing guidelines:

  • Do not run automated scanners on other customer projects. Running automated scanners can run up costs for our users. Aggressively configured scanners might inadvertently disrupt services, exploit vulnerabilities, lead to system instability or breaches and violate Terms of Service from our upstream providers. Our own security systems won't be able to distinguish hostile reconnaissance from whitehat research. If you wish to run an automated scanner, notify us at security@capgo.app and only run it on your own Capgo project. Do NOT attack projects of other customers.
  • 見つけた脆弱性や問題を利用してはなりません。たとえば、脆弱性を示すために必要以上のデータをダウンロードしたり、他の人のデータを削除したり変更したりしてはなりません。

報告ガイドライン:

  • ご報告は GitHub セキュリティ アドバイザリー:: からお送りください。 https://github.com/Cap-go/capgo/security/advisories/new
  • 問題を再現できる十分な情報を提供してください。そうすることで、できるだけ早く問題を解決できるようになります。
  • Capgo プラグインのセキュリティ レポートを受け付けてレビューしていますが、 code プラグインの有料ボーナスは @capgo/capacitor-updater 限定です。 Capgo プラグインは有料製品の範囲外なので、無料で使用できますが、レビューは行われます。

漏洩ガイドライン:

  • お客様を保護するために、問題を他の人に明らかにしてはなりません。問題を調査し、対処し、お客様に知らせるまでに、問題を他の人に明らかにしてはなりません。
  • Capgo についての研究を公開したい場合は、会議、ブログ、またはその他の公開フォーラムで、30 日以上前の公開日までに、草案を送信してレビューと承認を求めてください。次の情報は含めることができません。
    • Capgo の顧客プロジェクトに関するデータ
    • Capgo の顧客データ
    • Capgo の従業員、契約社員、パートナーの情報

What we promise:

  • 7日以内に、報告内容の評価と解決予定日を含む回答を提供します。
  • 上記の指示に従った場合、報告に関してはあなたに対して法的措置をとることはありません。
  • 報告内容は厳密に機密扱いとなり、第三者にあなたの個人情報を提供することはありません。
  • 問題の解決状況については、常にあなたに情報を提供します。
  • 問題の報告に関する公の情報において、問題発見者としてあなたの名前を公表します (あなたが異議を唱える場合は除きます)。
  • 共有されたログに漏洩したデータが表示された場合、データは問題の修正に使用されるデバッグ情報として扱われ、報復や復讐の理由にはなりません。

問題を解決するには、できるだけ早く解決することを目指しており、問題が解決された後、最終的な問題の発表に積極的に参加したいと思います。