Skip to content

Commit

Permalink
SECURITY.md file
Browse files Browse the repository at this point in the history
  • Loading branch information
Pierre RAMBAUD committed Dec 12, 2019
1 parent 9fbba52 commit 3e194b0
Showing 1 changed file with 25 additions and 0 deletions.
25 changes: 25 additions & 0 deletions .github/SECURITY.md
@@ -0,0 +1,25 @@
# Security Policy

The PrestaShop team and community take security bugs in PrestaShop seriously. We appreciate your efforts to responsibly disclose your findings

## Supported Versions

Security updates will typically only be applied to the latest release.

## Reporting a Vulnerability

Security issues can be reported by sending an email to security@prestashop.com, which will go to security team members.
The team will send a response indicating the next steps in handling your report.
After the initial reply to your report, the security team will keep you informed of the progress towards a fix and full announcement, and may ask for additional information or guidance.

When the security team receives a security bug report, they will assign it to a primary handler.
This person will coordinate the fix and release process, involving the following steps:

- Confirm the problem and determine the affected versions.
- Audit code to find any potential similar problems.
- Prepare fixes for all releases still under maintenance. These fixes will be released as fast as possible.


## Disclosure Policy

In general, public disclosure are made after the issue has been fully identified and a patch is readyu to be released.

0 comments on commit 3e194b0

Please sign in to comment.