Please report security issues privately by email to support@tackquote.com. Do not open a public GitHub issue, pull request or discussion for a suspected vulnerability.
Include, where you can:
- what is affected (file, endpoint or setting) and the version you tested;
- steps to reproduce, or a proof of concept;
- the impact you expect.
We will acknowledge your report, investigate, and tell you when a fix is released. Please give us a reasonable chance to fix the issue before you disclose it publicly.
Security fixes are made for the latest release of both release assets, the plugin and the Shopware Cloud app (https://github.com/tackquote/shopware/releases/latest). Fixes are released as a new version; older releases are not patched.
The TackQuote platform API (api.tackquote.com) is covered by this policy
too; report issues in it to the same address.