1. Kaip pranešti
Rašykite arunas.jurgelaitis@litgrid.eu, tema „G-Procure - saugumo spraga“. Lietuvių arba anglų kalba.
- Kuris adresas ar įrankis paveiktas.
- Žingsniai, kaip spragą pakartoti, ir naršyklė.
- Ką pavyko pasiekti (poveikis); jei galite - koncepcijos įrodymas.
Nesiųskite konfidencialių pirkimų dokumentų ir kitų asmenų duomenų - jų įrodymui nereikia.
Mašinoms skaitomas kontaktas - /.well-known/security.txt (RFC 9116).
2. Ką pažadame
- Gavimą patvirtinsime per 5 darbo dienas.
- Įvertinsime ir pranešime, ar spraga patvirtinta ir kada planuojame ją ištaisyti.
- Pranešime, kai ištaisysime. Jūsų sutikimu paminėsime jus kaip pranešusį.
Prašome spragos neviešinti, kol ji neištaisyta. Jei taisymas užtrunka ilgiau kaip 90 dienų, dėl viešinimo laiko susitarsime kartu.
3. Kam taikoma
Taikoma
g-procure.com- visi puslapiai ir įrankiai;api.g-procure.com- G-Procure tarpinis serveris;epd-api.g-procure.com- viešo EPD įrankio tarpinis taškas;- viešas kodas github.com/Jurgelaitis/g-procure (pvz. jame rastas slaptas raktas).
Netaikoma
- trečiųjų šalių paslaugos (GitHub, Cloudflare, Hetzner, Anthropic, Google Fonts, CVP IS, e-tar) - joms praneškite tiesiogiai;
- automatinių skenerių ataskaitos be patvirtinto poveikio.
4. Taisyklės tyrėjams
- Netrikdykite paslaugos ir nesiųskite masinių užklausų - ypač į DI kelius: kiekviena DI užklausa kainuoja.
- G-Procure naudotojų duomenys saugomi tik jų naršyklėse. Tikrinkite tik su savo duomenimis ir savo naršykle; kitų žmonių įrenginių ir paskyrų nelieskite.
- Radę prieigą prie duomenų ar sistemos - sustokite, nieko nekeiskite, nesaugokite daugiau, nei reikia įrodymui, ir praneškite.
- Nenaudokite socialinės inžinerijos, fizinės prieigos ir šlamšto; nespėliokite slaptažodžių.
5. Sąžiningas tyrimas
Jei tyrimą atliekate sąžiningai ir laikotės šių taisyklių, laikysime jį leistinu ir dėl jo nesikreipsime į teisėsaugos institucijas. Šis leidimas netaikomas trečiųjų šalių sistemoms.
Kaip G-Procure valdo DI ir kitus incidentus: DI valdymas ir rizikų kontrolė; kokie duomenys tvarkomi: Privatumo pranešimas.
Paskelbta 2026-10-06. Peržiūrima kas pusmetį.
1. How to report
Write to arunas.jurgelaitis@litgrid.eu with the subject “G-Procure - security vulnerability”, in English or Lithuanian.
- Which address or tool is affected.
- Steps to reproduce, and the browser.
- What you were able to achieve (impact); a proof of concept if you can.
Do not send confidential procurement documents or other people's data - they are not needed as proof.
Machine-readable contact: /.well-known/security.txt (RFC 9116).
2. What we promise
- We acknowledge receipt within 5 working days.
- We assess the report and tell you whether the vulnerability is confirmed and when we plan to fix it.
- We let you know when it is fixed. With your consent, we credit you as the reporter.
Please do not disclose the vulnerability until it is fixed. If a fix takes longer than 90 days, we will agree on the disclosure date together.
3. Scope
In scope
g-procure.com- all pages and tools;api.g-procure.com- the G-Procure relay server;epd-api.g-procure.com- the relay for the public EPD tool;- the public code github.com/Jurgelaitis/g-procure (for example, a secret key found in it).
Out of scope
- third-party services (GitHub, Cloudflare, Hetzner, Anthropic, Google Fonts, CVP IS, e-tar) - report to them directly;
- automated scanner reports without demonstrated impact.
4. Rules for researchers
- Do not disrupt the service or send bulk requests - especially to the AI routes: every AI request costs money.
- G-Procure user data is stored only in the users' own browsers. Test only with your own data and your own browser; do not touch other people's devices or accounts.
- If you gain access to data or a system - stop, change nothing, keep no more than needed as proof, and report.
- No social engineering, physical access or spam; do not guess passwords.
5. Good-faith research
If you research in good faith and follow these rules, we will consider your research authorised and will not refer it to law enforcement. This authorisation does not cover third-party systems.
How G-Procure governs AI and other incidents: AI governance and risk control; which data is processed: Privacy notice.
Published on 2026-10-06. Reviewed every six months.