Skip to content

Security: minnek-digital-studio/shopify-template

Security

SECURITY.md

Security

GPG

All the commits in this project need to be pushed using SSH and a GPG sign commit. Follow the instructions on how to use a GPG key and set up your Git environment to sign the commits to verify your identity in the organization.

Reporting Potential Security Issues

If you have encountered a potential security vulnerability in this project, please report it or create a pull request to fix it. We will work with you to verify the vulnerability and patch it.

When reporting issues, please provide the following information:

  • Component(s) affected
  • A description indicating how to reproduce the issue
  • A summary of the security vulnerability and impact
  • We request that you contact us via the email address above and give the project contributors a chance to resolve the vulnerability and issue a new release prior to any public exposure; this helps protect the project's users, and provides them with a chance to upgrade and/or update in order to protect their applications.

Policy

If we verify a reported security vulnerability, our policy is:

  • We will patch the current release branch, as well as the immediate prior minor release branch.
  • After patching the release branches, we will immediately issue new security fix releases for each patched release branch.
  • A security advisory will be released on the project website detailing the vulnerability, as well as recommendations for end-users to protect themselves. Security advisories will be listed at project changelog.

There aren’t any published security advisories