diff --git a/.github/SECURITY.md b/.github/SECURITY.md new file mode 100644 index 0000000000000..5954f16ca8fd2 --- /dev/null +++ b/.github/SECURITY.md @@ -0,0 +1,25 @@ +# Security Policy + +The PrestaShop team and community take security bugs in PrestaShop seriously. We appreciate your efforts to responsibly disclose your findings + +## Supported Versions + +Security updates will typically only be applied to the latest release. + +## Reporting a Vulnerability + +Security issues can be reported by sending an email to security@prestashop.com, which will go to security team members. +The team will send a response indicating the next steps in handling your report. +After the initial reply to your report, the security team will keep you informed of the progress towards a fix and full announcement, and may ask for additional information or guidance. + +When the security team receives a security bug report, they will assign it to a primary handler. +This person will coordinate the fix and release process, involving the following steps: + + - Confirm the problem and determine the affected versions. + - Audit code to find any potential similar problems. + - Prepare fixes for all releases still under maintenance. These fixes will be released as fast as possible. + + +## Disclosure Policy + +In general, public disclosure are made after the issue has been fully identified and a patch is readyu to be released.