Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description of Organization
Reason for PSL Inclusion
DNS verification via dig
Run Syntax Checker (make test)
Each domain listed in the PRIVATE section has and shall maintain at least two years remaining on registration.
Description of Organization
Organization Website: https://www.shopify.com
My name is Alex, I'm an Application Security Engineer at Shopify.
Shopify is an e-commerce organization. We provide merchants with tools and services to sell their products online and/or in-person, with the ultimate goal of making commerce better for everyone.
Reason for PSL Inclusion
In addition to allowing merchants to purchase and/or connect their domain name to their shops, we provision all new merchants with a
*.myshopify.com
subdomain. Because of this, requests between shops using*.myshopify.com
domains are considered to be samesite, leaving them open to CSRF.We're looking to add
myshopify.com
to the Public Suffix List to improve cookie security for all of our merchants who do not yet make use of a custom domain.DNS Verification via dig
make test
Tests passed OK.