We release patches for security vulnerabilities for the following versions:
| Version | Supported |
|---|---|
| 1.x.x | ✅ |
If you discover a security vulnerability within this package, please send an email to Igor Sazonov at sovletig@gmail.com. All security vulnerabilities will be promptly addressed.
Please do not publicly disclose the issue until it has been addressed by the team.
When reporting a vulnerability, please include:
- A description of the vulnerability
- Steps to reproduce the issue
- Potential impact
- Any suggested fixes (if applicable)
- Initial Response: Within 48 hours
- Status Update: Within 7 days
- Fix Timeline: Varies based on severity, but critical issues will be prioritized
When using this SDK:
- Never commit API tokens to version control
- Use environment variables for sensitive configuration
- Use test tokens in development environments
- Rotate API tokens regularly
- Validate all user input before passing to the SDK
- Keep the package updated to the latest version
- Use HTTPS for all API communications (enforced by default)
When a security vulnerability is reported and confirmed:
- A fix will be developed and tested
- A security advisory will be published
- A new version will be released
- Credit will be given to the reporter (unless anonymity is requested)
Thank you for helping keep Shippo PHP SDK and its users safe!