Skip to content

Security: yusufarbc/e-commerce-cloudflare

SECURITY.md

Security Policy

We take the security of E-Market very seriously. If you believe you have found a security vulnerability in this project, please report it to us privately through the channel detailed below.

Please do not report security vulnerabilities via public GitHub issues.


🛡️ Supported Versions

We actively provide security updates for the following versions of E-Market:

Version Supported
1.x.x Active Support
< 1.0.0 Unsupported

📥 Reporting a Vulnerability

If you identify a security issue, please notify us using one of the following secure reporting methods:

  1. Email: Send a detailed email to security@e-market-domain.com with the subject prefix [Vulnerability Report].
  2. GitHub Private Vulnerability Reporting: Go to the repository's "Security" tab, select "Advisories", and click "Report a vulnerability".

What to Include in Your Report:

  • A clear description of the vulnerability, the components involved, and the potential impact.
  • Detailed step-by-step instructions (or proof-of-concept scripts) to reproduce the vulnerability.
  • System details (operating system, browser, Node.js version, and wrangler configuration).

⚡ Our Response Timeline

  • Triage: We will acknowledge receipt of your report within 24 hours and confirm the vulnerability within 72 hours.
  • Remediation: We aim to release a patched version within 14 days of verification, keeping you updated on our progress.
  • Disclosure: Once the patch is released, we will publicly disclose the vulnerability via a GitHub Security Advisory, giving you full credit for the discovery (unless anonymity is requested).

There aren't any published security advisories