Skip to content

Security: saleor/macaw-ui

SECURITY.md

Security Policy

Warning

DO NOT report security vulnerabilities using a public GitHub issue.

If you believe you've found a security issue, please contact us through one of the following methods:

  • Using GitHub security advisories: https://github.com/saleor/<repository-name>/security/advisories (replace <repository-name>)
  • Alternatively, through our mailing list: security@saleor.io

Whichever method you choose, you will be credited as the reporter once the announcement is published.

Guidelines

A report must:

  • Include a clear description of the issue
  • Include reproduction steps that allow us to verify the behavior
  • Include affected version(s) and environment details (versions, OS, tools, configurations)
  • Mention whether you are willing to review the patches before their publication
  • Be self-contained (no file attachments nor download links). Reports requiring to open arbitrary files or links may not be accepted.

Reports that lack these elements may be considered incomplete and may be closed without follow-up, reports may also be closed if the submitter does not engage to follow-ups.

Automated Reports

We do not accept:

  • Low-effort reports
  • Reports generated by automated tools or AI systems that weren't manually verified by a human
  • Raw output from scanners, prompts, or automated tooling that didn't go through human analysis or human validation
  • Reports that are bulk-submitted without context or verification
  • Reports that are not addressing feedback or questions

You should:

  • Clearly disclose if you used AI to create the vulnerability report. This ensures transparency and accountability.
  • Explicitly confirm that you manually verified the findings and the contents. Reports that were not manually verified may be get rejected without follow-ups.

No Monetary Rewards

We do not have a bounty program in place, so we cannot offer monetary rewards for any reported problems.

There aren't any published security advisories