DoRms 인증
도름스 보안 체크리스트 충족
도름스가 자체적으로 점검한 결과예요. 정부·교육청의 공식 인증은 아니지만, 전송 보안·보안 헤더·정보 유출·데이터 접근 같은 기본 보안 항목을 도름스 서버가 직접 검사해서 확인했어요.
식별번호
DSR-2026-DEA1572A
대상 앱
발급일
2026.07.09
마지막 확인일
2026.07.10
만료일
2027.01.06
보안 점수 · 등급
100점 · A+
도름스가 직접 확인한 항목
30개도름스 서버가 앱 주소에 직접 접속해 관찰한 결과예요.
Content-Security-Policy
content-security-policy: default-src 'none'; base-uri 'self'; child-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/; connect-src 'self' uploads.github.com www.githubstatus.com collector.github.com raw.githubusercontent.com api.github.com github-cloud.s3.amazonaws.com github-production-repository-file-5c1aeb.s3.amazonaws.com github-production-upload-manifest-file-7fdce7.s3.amazonaws.com github-production-user-asset-6210df.s3.amazonaws.com *.rel.tunnels.api.visualstudio.com wss://*.rel.tunnels.api.visualstudio.com github.githubassets.com objects-origin.githubusercontent.com copilot-proxy.githubusercontent.com proxy.individual.githubcopilot.com proxy.business.githubcopilot.com proxy.enterprise.githubcopilot.com *.actions.githubusercontent.com wss://*.actions.githubusercontent.com productionresultssa0.blob.core.windows.net productionresultssa1.blob.core.windows.net productionresultssa2.blob.core.windows.net productionresultssa3.blob.core.windows.net productionresultssa4.blob.core.windows.net productionresultssa5.blob.core.windows.net productionresultssa6.blob.core.windows.net productionresultssa7.blob.core.windows.net productionresultssa8.blob.core.windows.net productionresultssa9.blob.core.windows.net productionresultssa10.blob.core.windows.net productionresultssa11.blob.core.windows.net productionresultssa12.blob.core.windows.net productionresultssa13.blob.core.windows.net productionresultssa14.blob.core.windows.net productionresultssa15.blob.core.windows.net productionresultssa16.blob.core.windows.net productionresultssa17.blob.core.windows.net productionresultssa18.blob.core.windows.net productionresultssa19.blob.core.windows.net github-production-repository-image-32fea6.s3.amazonaws.com github-production-release-asset-2e65be.s3.amazonaws.com insights.github.com wss://alive.github.com wss://alive-staging.github.com api.githubcopilot.com api.individual.githubcopilot.com api.business.githubcopilot.com api.enterprise.githubcopilot.com wss://production-copilot-host.webpubsub.azure.com; font-src github.githubassets.com; form-action 'self' github.com gist.github.com copilot-workspace.githubnext.com objects-origin.githubusercontent.com; frame-ancestors 'none'; frame-src viewscreen.githubusercontent.com notebooks.githubusercontent.com; img-src 'self' data: blob: github.githubassets.com media.githubusercontent.com camo.githubusercontent.com identicons.github.com avatars.githubusercontent.com private-avatars.githubusercontent.com github-cloud.s3.amazonaws.com objects.githubusercontent.com release-assets.githubusercontent.com secured-user-images.githubusercontent.com user-images.githubusercontent.com private-user-images.githubusercontent.com opengraph.githubassets.com marketplace-screenshots.githubusercontent.com copilotprodattachments.blob.core.windows.net/github-production-copilot-attachments/ github-production-user-asset-6210df.s3.amazonaws.com customer-stories-feed.github.com spotlights-feed.github.com explore-feed.github.com objects-origin.githubusercontent.com *.githubusercontent.com; manifest-src 'self'; media-src github.com user-images.githubusercontent.com secured-user-images.githubusercontent.com private-user-images.githubusercontent.com github-production-user-asset-6210df.s3.amazonaws.com gist.github.com github.githubassets.com; script-src github.githubassets.com; style-src 'unsafe-inline' github.githubassets.com; upgrade-insecure-requests; worker-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/
Strict-Transport-Security
strict-transport-security: max-age=31536000; includeSubdomains; preload
클릭재킹 방어(X-Frame-Options / frame-ancestors)
x-frame-options: deny
X-Content-Type-Options: nosniff
x-content-type-options: nosniff
Referrer-Policy
referrer-policy: no-referrer-when-downgrade
Permissions-Policy
누락: permissions-policy
서버/프레임워크 버전 노출
x-powered-by 미노출(양호)
HTTPS 강제(HTTP→HTTPS 리다이렉트)
HTTP 요청이 HTTPS로 리다이렉트됨 (HTTP 301 -> https://github.com/)
SSL 인증서 유효
TLS 연결 성공 (TLSv1.3)
구버전 TLS 미사용
TLS 버전 양호: TLSv1.3
쿠키 보안 플래그(HttpOnly/Secure)
쿠키 HttpOnly/Secure 설정됨
민감 파일 노출(.env/.git)
민감 파일(.env/.git) 노출 없음
설정 파일 노출
설정 파일 비노출
소스맵 노출
소스맵 참조 없음
에러 스택트레이스 노출
스택트레이스 노출 없음
Mixed Content
mixed content 없음
CORS 설정
CORS가 임의 Origin을 허용하지 않음(양호)
페이지 제목
<title> 있음
설명 메타
설명 메타
모바일 viewport
viewport 메타
Open Graph
Open Graph 태그
canonical
canonical 링크
응답 속도
응답 시간 743ms
문서 크기
문서 크기 324KB
압축
압축: gzip
개인정보처리방침
개인정보처리방침 발견(link: https://docs.github.com/site-policy/privacy-policies/github-privacy-statement)
이용약관
이용약관 발견(link: https://docs.github.com/site-policy/github-terms/github-terms-of-service)
연락처
연락처/문의 정보 있음
익명 접근 차단(Supabase RLS)
Supabase 공개 자격을 앱에서 찾지 못함(비-Supabase 앱이거나 자격 비노출) — RLS 실측 생략
미인증 API 접근
앱에서 내부 API 경로를 찾지 못함 — 미인증 호출 프로브 생략
제작자 자기점검
0개제작자가 스스로 점검해 적은 내용이에요. 도름스가 코드를 직접 확인하지는 않았어요.
제작자가 따로 적은 자기점검 항목이 없어요.