Skip to content

Security: YouCap/Youcap-Extension

Security

SECURITY.md

Security Policy

Scope

Out-of-scope vulnerabilities:

  1. Attacks against YouCap personnel, facilities or devices.
  2. Attacks against third-party assets, including Github, Google, or YouTube.
  3. Vulnerabilities in a browser rather than the extension.

Safe Harbor Policy

Should a researcher suffer legal consequences due to security research made in good faith, we will do everything we can to the extent that is possible under the law to protect you from legal harm. However, please ensure that you adhere closely to this security policy. Never make unauthorized modifications to data and never perform research under this policy on third-party assets. Should you come into unauthorized contact with sensitive or otherwise restricted data, please halt your research and immediately file a report.

Supported Versions

The following table outlines which versions receive active updates and thus are included within the scope of this security policy.

Version Supported
1.0.x

Reporting a Vulnerability

Any security vulnerability report must include the following if applicable:

  1. Your name and email address (unless you wish to remain anonymous). Also include your organization if research was conducted as part of an organizational group.
  2. The browser, browser version, and extension version.
  3. The URL(s) that the vulnerability was tested against.
  4. A description of the vulnerability.
  5. Steps to reproduce the vulnerability.
  6. The potential security impact. (Including a CVSS score is helpful but does not meet this requirement in full)
  7. A working proof of concept, if possible.
  8. Whether access was made to any data.

Reward

Due to YouCap's status as a non-profit, we are unable to offer a bug bounty at this time. However, with your approval we'll include you among our site's list of security researchers.

There aren’t any published security advisories