Security Policy
Supported Versions
| Version | Supported |
|---|---|
| 2.0.x | :white_check_mark: |
Reporting a Vulnerability
We take security vulnerabilities seriously. If you discover a security vulnerability, please report it responsibly.
How to Report
Please do NOT report security vulnerabilities through public GitHub issues.
Instead, please report them via one of the following methods:
- Email: help@ridewithlasso.com
- GitHub Security Advisory: Use GitHub's private vulnerability reporting feature (if enabled)
What to Include
When reporting a vulnerability, please include:
- A description of the vulnerability
- Steps to reproduce the issue
- Potential impact
- Suggested fix (if you have one)
Response Timeline
- Initial Response: Within 48 hours
- Status Update: Within 7 days
- Fix Timeline: Depends on severity, but we aim to address critical issues within 30 days
Scope
This security policy applies to:
- The Lasso Shopify app codebase
- Cloudflare Workers deployment
- Shopify app integration
- iMessage/LinqApp integration
Out of Scope
- Issues in dependencies (please report to the upstream project)
- Denial of service attacks
- Social engineering attacks
- Physical security issues
Security Best Practices
- Never commit secrets or API keys
- Use environment variables for sensitive configuration
- Follow Shopify's security guidelines
- Keep dependencies up to date
- Use HTTPS for all external communications
Acknowledgments
We appreciate responsible disclosure and will acknowledge security researchers who help us improve our security posture.