We take the security of E-Market very seriously. If you believe you have found a security vulnerability in this project, please report it to us privately through the channel detailed below.
Please do not report security vulnerabilities via public GitHub issues.
We actively provide security updates for the following versions of E-Market:
| Version | Supported |
|---|---|
| 1.x.x | Active Support |
| < 1.0.0 | Unsupported |
If you identify a security issue, please notify us using one of the following secure reporting methods:
- Email: Send a detailed email to security@e-market-domain.com with the subject prefix
[Vulnerability Report]. - GitHub Private Vulnerability Reporting: Go to the repository's "Security" tab, select "Advisories", and click "Report a vulnerability".
- A clear description of the vulnerability, the components involved, and the potential impact.
- Detailed step-by-step instructions (or proof-of-concept scripts) to reproduce the vulnerability.
- System details (operating system, browser, Node.js version, and wrangler configuration).
- Triage: We will acknowledge receipt of your report within 24 hours and confirm the vulnerability within 72 hours.
- Remediation: We aim to release a patched version within 14 days of verification, keeping you updated on our progress.
- Disclosure: Once the patch is released, we will publicly disclose the vulnerability via a GitHub Security Advisory, giving you full credit for the discovery (unless anonymity is requested).