Thanks for helping keep Capgo and @capgo/capacitor-updater safe.
Do not use Discord, GitHub Issues, or any public forum.
Open a private advisory here: https://github.com/Cap-go/capacitor-updater/security/advisories/new
Before you file, use the Capgo advisory checklist: https://github.com/Cap-go/.github/blob/main/ADVISORY_TEMPLATE.md
Reporting requirements, out-of-scope rules, what happens after you report, embargo, and bounty payout gates live in the Cap-go org security policy: https://github.com/Cap-go/.github/blob/main/SECURITY.md
Public researcher pages:
This plugin repository is in scope for Capgo's open-source bug bounty (see the bounty page for amounts and rules).
Reports in these classes are closed (see org policy and https://capgo.app/security/ for the full list):
- Unauthenticated
channel_selfset, and designed no-API-key behavior for/updatesand/stats - Uploader mislabeling encryption on
external_urlbundles - Duplicates, already-fixed-on-
mainwithout a new exploit path, incomplete drafts
Capgo pays eligible bounties only after the fix is released and you have verified the fix. Linking or opening a PR alone is not enough. See https://capgo.app/bug-bounty/.