Skip to content

Security: stechdrive/Insta360Convert-GUI

SECURITY.md

Security policy / セキュリティ方針

Reporting a vulnerability / 脆弱性の報告

Use GitHub's private vulnerability reporting. Include the affected version, operating system, tool versions, impact, and a harmless reproduction. Do not attach credentials or private media, or post an exploitable issue publicly before coordination.

GitHubの非公開報告窓口に、対象バージョン・OS・外部ツールのバージョン・影響・無害な再現手順をお知らせください。認証情報や非公開の動画は添付せず、調整前に悪用可能な詳細を公開Issueへ投稿しないでください。

Running the application / 実行時の前提

  • Use a supported Python release (3.11 or newer), Tk 8.6 or newer, and current patched builds of FFmpeg/ffprobe and optional COLMAP/GLOMAP. The app uses Python's standard library; it does not install Python packages or automatically install updates.

  • Obtain executables from trusted distributors. On Windows select the actual .exe, not a .bat/.cmd wrapper. Automatic tool lookup uses absolute PATH directories outside the current working directory. Keep the application and installed tools separate from untrusted downloads; do not run as administrator.

  • Media input accepts ordinary local video/image formats, including MP4/MOV/INSV, MKV/WebM, AVI and JPEG/INSP. Network protocols, playlists and script demuxers are disabled. This restricts FFmpeg inputs; it does not sandbox native codecs, filesystem shares, explicitly selected tools, or a modified Python checkout.

  • The update checker contacts the fixed GitHub releases API over verified HTTPS and only displays release information. Downloading/installing a release remains a user action.

  • Pythonはサポート中の3.11以降、Tkは8.6以降を使用し、FFmpeg/ffprobeと任意のCOLMAP/GLOMAPにはセキュリティ修正済みの版を適用してください。Pythonの外部パッケージ依存はなく、自動インストールや自動更新は行いません。

  • 実行ファイルは信頼できる配布元から入手し、Windowsでは.bat/.cmdでなく実体の.exeを選択してください。自動検索ではカレントディレクトリ以外の絶対PATHを使用します。アプリとツールの配置先を未確認のダウンロードと分け、管理者権限で実行しないでください。

  • 入力は通常のローカル動画・画像に限定し、ネットワークプロトコル、プレイリスト、スクリプト形式は拒否します。この制限はFFmpegの入力境界であり、ネイティブコーデック、共有フォルダ、明示的に選択したツール、改変されたPythonコードを隔離するものではありません。

  • 更新確認は固定のGitHub APIへ証明書検証付きHTTPSで接続し、情報を表示します。ダウンロードとインストールはユーザー操作です。

Repository maintenance / 公開リポジトリの保守

  • Keep secret scanning, push protection and Dependabot alerts enabled. .gitignore is a guardrail, not a substitute for checking staged changes; rotate any credential that has been committed, including in old history or release archives.

  • If adding CI, use hosted runners for external pull requests, minimal token permissions, full commit SHAs for actions, and no secrets for untrusted code. Do not execute fork code from privileged pull_request_target or workflow_run jobs.

  • Keep personal credentials out of this repository and its test fixtures. Audit account passkeys/2FA, sessions, PAT permissions and connected apps in GitHub account settings. Repository settings do not prove that the account is secure.

  • Secret scanning・Push protection・Dependabot通知を維持してください。.gitignoreだけに頼らずコミット内容を確認し、履歴や配布ZIPに認証情報を含めた場合は失効・再発行してください。

  • CIを追加する場合、外部PRにはGitHubホストのRunnerと最小権限トークンを使い、Actionsを完全なコミットSHAに固定してください。外部コードに秘密情報を渡したり、権限付きのpull_request_target/workflow_runから実行したりしないでください。

  • GitHubアカウントのパスキー・2要素認証・セッション・PAT権限・連携アプリはアカウント設定で確認してください。リポジトリの保護設定だけではアカウント全体の安全性は確認できません。

Regression checks / 回帰確認

python -m unittest discover -s tests -v

The tests use the standard library. FFmpeg integration tests run when FFmpeg/ffprobe are available in PATH; otherwise they are marked skipped. They cover executable resolution, Windows batch rejection, bounded update responses, media probing, and CPU PNG/JPEG/MP4/COLMAP-rig output. GPU conversion and the external COLMAP/GLOMAP pipeline require separate checks.

テストは標準ライブラリのみで実行できます。FFmpeg/ffprobeがPATHにない環境では実ファイルの変換テストはスキップされます。GPU変換と外部COLMAP/GLOMAPの全パイプラインは別途確認してください。

There aren't any published security advisories