メインコンテンツにジャンプ

セキュリティポリシー

連絡先: https://github.com/Cap-go/capgo/security/advisories/new
Canonical: https://capgo.app/security.txt

At Capgo, we consider the security of our systems a top priority. However, no matter how much effort we put into system security, there can still be vulnerabilities present.

脆弱性を発見した場合、できるだけ早く対処することができます。私たちのクライアントやシステムをよりよく保護するために、私たちに協力していただけるようお願いします。

範囲外の脆弱性:

  • クリックジャッキングが行われないページの場合。
  • 未認証/ログアウト/ログインのCSRF。
  • 物理的にユーザーのデバイスにアクセスすることや、MITM攻撃を必要とする攻撃。
  • 社会的エンジニアリングを必要とする攻撃。
  • サービス停止攻撃 (DoS) によるサービス中断の可能性
  • コンテンツの偽装やテキストの挿入に関する問題は、攻撃ベクトルを表示せずに HTML/CSS を変更できない場合
  • メールの偽装
  • DNSSEC、CAA、CSP ヘッダーの欠如
  • 非機密性の cookie に対して Secure または HTTP only フラグの欠如
  • 死リンク
  • ユーザー情報の漏洩
  • SSRF or DNS spoofing reports against webhooks or website preview. These features run on serverless infrastructure and cannot be used to reach private Capgo infrastructure, so they are not exploitable in our environment.
  • User-owned application code or project configuration that Capgo does not own, ship, or control, including files such as capacitor.config.ts, config.capacitor.ts, app source code, and environment-specific settings.
  • Access to Capgo bundle files or proof that bundle files can be downloaded. Bundle files are public web assets, users are informed of this, and access to them is not considered a data breach.

Supabase Auth の既知の制限

Some findings are repeatedly reported and tied to Supabase Auth behavior. These are only treated as Supabase-side issues when they can be reproduced in a shared Supabase demo project configured like ours and when a Supabase configuration change fixes the behavior without changing Capgo security rules. If the fix requires changing Capgo-owned SQL, RPCs, RLS policies, functions, or app logic, that is a Capgo issue and should be reported to us.

  • 報告では、再現可能なデモの Supabase プロジェクト、ステップが含まれ、Capgo の設定と動作を示すものでなければなりません。
  • 報告では、正確な修正パスが含まれます: Supabase の設定/構成変更が問題を解決するもの、または Capgo 所有の code /構成オブジェクトが変更する必要があるものです。
  • アカウント/メールフローは、Supabase プロジェクトの設定 (例: メール確認が無効でキャプチャフローが使用されている場合) に対して検証されます。
  • パスワードとメール/パスワードの更新フローは、現在の Supabase Auth セッションと再検証設定に依存する場合があります。
  • If a demo project proves a concrete Supabase-side fix with no Capgo policy change, or shows a concrete Capgo-owned defect, we review it as actionable.

テストガイドライン:

  • 自動スキャナを他の顧客プロジェクトに実行しないでください。自動スキャナを実行すると、ユーザーにコストがかかります。Aggressively 設定されたスキャナは、サービスを混乱させたり、脆弱性を利用したり、システムのinstabilityを引き起こしたり、セキュリティ上の違反を引き起こしたりする可能性があります。上流のプロバイダーから提供されるTerms of Serviceを違反する可能性があります。Capgo のセキュリティシステムは、白帽リサーチと敵対的な偵察を区別できません。自動スキャナを実行したい場合は、security@capgo.app に連絡してください。ただし、自動スキャナを実行する場合は、自分の Capgo プロジェクトのみに実行してください。
  • 脆弱性や問題を発見した場合、その利用は行わないでください。例えば、脆弱性を示すために必要なデータより多くのデータをダウンロードしたり、他の人のデータを削除したり、変更したりしてはいけません。

報告ガイドライン:

  • セキュリティ・アドバイザリー:: <a href="https://GitHub.com/Cap-go/__CAPGO_KEEP_1__/security/advisories/new">https://GitHub.com/Cap-go/__CAPGO_KEEP_1__/security/advisories/new</a> https://github.com/Cap-go/capgo/security/advisories/new
  • Capgoプラグインのセキュリティレポートを受け付けてレビューしますが、@__CAPGO_KEEP_2__/__CAPGO_KEEP_3__-updaterで有料のボーナスが受け取れるのはCapgoプラグインのみです。他のCapgoプラグインは無料で利用でき、有料製品の範囲外なので、レビューされますが未払いのレポートとなります。
  • We accept and review security reports for Capgo plugins, but paid bounties for plugin code are limited to @capgo/capacitor-updater. Other Capgo plugins are free to use and are not part of our paid product offering, so reports for them are reviewed but unpaid.

問題を他の人に明らかにするのを避けるために、問題を解決し、影響を受けた顧客に知らせるまで、顧客を保護するために、問題を他の人に明らかにしないでください。

  • Capgoについての研究を公開したい場合は、発表予定日から30日前までに、レビューと承認のために、draftを共有してください。次の情報は含めないでください。
  • If you want to publicly share your research about Capgo at a conference, in a blog or any other public forum, you should share a draft with us for review and approval at least 30 days prior to the publication date. Please note that the following should not be included:
    • Data regarding any Capgo customer projects
    • Capgo customers&#39; data
    • Information about Capgo employees, contractors or partners

【保証事項】

  • 7営業日以内に、報告内容の評価と解決予定日を含む回答を提供します。
  • 報告の際に指示に従った場合、法的措置を取ることはありません。
  • 報告内容は厳密に機密扱いとなり、第三者に個人情報を提供することはありません。
  • 問題の解決状況について、常に情報を提供します。
  • 問題の発見者として、公表される情報に名前を表示します (あなたの意志に従う場合を除きます)。
  • 共有されたログに漏洩したデータが表示される場合、デバッグ情報として扱い、復讐や報復の理由にはなりません。

問題を解決することを最優先し、問題が解決された後も最終的な公表に積極的に参加したいと考えています。