Skip to content

Commit 93b3cf3

Browse files
Merge pull request mendix#10682 from mendix/nc-update-qsm
Update QSM
2 parents 239a954 + b098389 commit 93b3cf3

1 file changed

Lines changed: 2 additions & 6 deletions

File tree

content/en/docs/marketplace/upload-content/governance-process.md

Lines changed: 2 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -20,18 +20,14 @@ Mendix checks the following:
2020
* The licenses used in the uploaded *.mpk* files, using the [Fossology](https://fossology.osuosl.org/repo/) tool .
2121
There should be no use of GPL, LGPL, or MPL licenses.
2222
For more details, refer to [Open-Source Software Licenses](/appstore/submit-content/#license).
23-
* For malware in the *.mpk* files, using the [VirusTotal](https://www.virustotal.com/gui/home/upload) tool.
24-
* For third-party vulnerabilities, using the [Snyk](https://snyk.io/) tool.
25-
* That the component can be used without errors in a specific Studio Pro version, if the component is a widget, a module, a connector, or an industry template.
26-
* That the documentation mentions all the details per the template, for example, dependencies, configuration, and how to use the component.
27-
* That the grammar, alignment, and spelling for the component's description and documentation are correct.
23+
* For third-party vulnerabilities, using QSM. If critical or high vulnerabilities are found, the component is rejected.
2824
* That the logo is related to the component's functionality.
2925
* That the screenshots are related to the configuration required to use the component in the end-user's app.
3026

3127
It may sometimes take a few iterations for a component to be approved, depending on the issues identified. To avoid a high number of necessary iterations, make sure you have followed the [Guidelines for Content Creators](/appstore/guidelines-content-creators/) and have performed the checks above before you submit a component for approval.
3228

3329
{{% alert color="info" %}}
34-
Review and approval by Mendix is required only for the first version of a publicly-listed component. Subsequent versions of a public component do not need review or approval by Mendix.
30+
All subsequently uploaded versions of a public component must be scanned and approved by Mendix.
3531

3632
Private Marketplace content does not require any review or approval.
3733
{{% /alert %}}

0 commit comments

Comments
 (0)