Skip to content

Security: scottgilmoredev/commerce-sync

Security

SECURITY.md

Security Policy

Supported Versions

We support and maintain the following versions of the project:

Version Supported
main
others

Please ensure you are always working from the latest version on the main branch for security updates.


Reporting a Vulnerability

If you discover a security vulnerability, please do not create a public issue.

Instead, report it responsibly by emailing: scott@scottgilmore.dev

Your report should include:

  • A detailed description of the vulnerability.
  • Steps to reproduce the issue.
  • Any potential fixes or mitigation strategies you can suggest.

We will:

  1. Confirm receipt of your report within 48 hours.
  2. Investigate and validate the issue.
  3. Provide an estimated timeline for a fix.
  4. Credit you in the release notes if you want.

Responsible Disclosure

We kindly ask that you:

  • Do not publicly disclose the vulnerability before it is fixed.
  • Do not attempt to exploit the vulnerability beyond what is necessary to demonstrate it.

Contact

For all security-related issues, contact: scott@scottgilmore.dev

There aren't any published security advisories