Configazeに影響する脆弱性、不正アクセス、顧客データの露出が疑われる問題は、Configaze専用のGoogleフォームから報告してください。一般的な利用方法や不具合についてはサポートページをご利用ください。
セキュリティ方針
この方針は、Jira Cloud上で動作するConfigazeアプリに適用されます。公開WebサイトとGoogleフォームはアプリの実行環境とは別であり、Jira設定データをフォームへ自動送信しません。
- アプリの処理と保存にはAtlassian Forgeを使用し、発行元が運営する外部app server・外部DBへアプリデータを送信しません。
- Jira管理者権限を各アプリ操作でサーバー側から確認し、確認できない場合は処理を拒否します。
- Custom Field設定の読み取りに必要なscopeだけを使用し、Jira設定を変更するwrite scopeを要求しません。
- Password、Personal Access Token、API token、共有Jira credentialを要求・保存しません。
- Custom Field名・説明、Snapshot名・メモ、Atlassian account ID、Snapshot内容を意図的にアプリログへ出力しないよう設計しています。
- 履歴は最大30 Snapshotに制限し、Jira管理者がアプリ内から全履歴を削除できます。
インシデント対応
報告を受けた場合、影響と緊急度を確認し、必要な封じ込め、修正、記録、関係者への連絡を行います。Atlassian Marketplace appに関するセキュリティインシデントは、適用されるAtlassianの報告要件に従ってAtlassianへ連絡します。調査に不要な顧客データの提出は依頼しません。
責任あるセキュリティテスト
責任ある報告: 所有していないデータ、または試験許可を得ていないデータへアクセスしないでください。サービス停止、データ破壊、他者への影響を伴う試験は行わないでください。
報告に含める情報
- 問題の概要と想定される影響
- 影響する画面、操作、または機能
- 再現に必要な最小限の手順
- 発生日時とtimezone
- 分かる場合は関連するAtlassian request ID
- 追加確認に応答できる連絡先
送信しない情報
Password、API token、billing information、Atlassian account ID、顧客のJira設定全文、個人情報・秘密情報を含む未加工Screenshotは送信しないでください。Googleフォームではファイル添付を受け付けません。追加資料が必要な場合は、最初の報告後に安全な共有方法を調整します。
Googleフォームを開く
フォームはGoogle Forms上で開きます。入力した情報はGoogleにより処理・保存されます。フォームの利用には、Configazeのプライバシーポリシーに加えてGoogleのプライバシーポリシーが適用されます。
Report suspected vulnerabilities, unauthorized access, or exposure of customer data affecting Configaze through the dedicated Configaze Google Form. For general usage questions or product issues, use the support page.
Security policy
This policy applies to the Configaze app running on Jira Cloud. The public website and Google Forms are separate from the app runtime, and the app does not automatically send Jira configuration data to a form.
- App processing and storage use Atlassian Forge. App data is not sent to an external application server or database operated by the publisher.
- Jira administrator permission is checked on the server side for app operations, and access is denied when authorization cannot be confirmed.
- The app requests only the scopes required to read custom field configuration and does not request a Jira configuration write scope.
- The app does not request or store passwords, Personal Access Tokens, API tokens, or shared Jira credentials.
- The app is designed not to intentionally log custom field names or descriptions, snapshot names or notes, Atlassian account IDs, or snapshot contents.
- History is limited to 30 snapshots, and a Jira administrator can delete all app history from within the app.
Incident handling
When a report is received, it is assessed for impact and urgency, followed as appropriate by containment, remediation, documentation, and communication with affected parties. Security incidents involving an Atlassian Marketplace app are reported to Atlassian in accordance with applicable Atlassian reporting requirements. Customer data that is not needed for an investigation will not be requested.
Responsible security testing
Responsible reporting: Do not access data that you do not own or have explicit permission to test. Do not perform testing that disrupts service, destroys data, or affects other people.
Information to include
- A concise summary and the potential impact
- The affected screen, action, or feature
- The minimum steps required to reproduce the issue
- When it occurred, including the time zone
- A related Atlassian request ID, if available
- Contact information for follow-up questions
Information not to send
Do not send passwords, API tokens, billing information, Atlassian account IDs, complete customer Jira configuration, or unredacted screenshots containing personal or confidential information. The Google Form does not accept file uploads. If supporting material is needed, a safer sharing method can be arranged after the initial report.
Open the Google Form
The form opens on Google Forms. Information you submit is processed and stored by Google. Use of the form is subject to Google's privacy policy in addition to the Configaze Privacy Policy.