{"id":15797847,"url":"https://github.com/grokify/app-stores-guide","last_synced_at":"2026-01-11T02:38:57.319Z","repository":{"id":142759156,"uuid":"341618125","full_name":"grokify/app-stores-guide","owner":"grokify","description":"Information on various App Stores and Marketplaces.","archived":false,"fork":false,"pushed_at":"2021-02-23T18:05:49.000Z","size":4,"stargazers_count":0,"open_issues_count":0,"forks_count":0,"subscribers_count":3,"default_branch":"master","last_synced_at":"2024-10-12T00:42:29.417Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/grokify.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2021-02-23T16:31:46.000Z","updated_at":"2021-02-23T18:32:08.000Z","dependencies_parsed_at":null,"dependency_job_id":"51732249-a174-4aa8-8d8a-6bf3bebc2284","html_url":"https://github.com/grokify/app-stores-guide","commit_stats":{"total_commits":9,"total_committers":1,"mean_commits":9.0,"dds":0.0,"last_synced_commit":"f0f532efff829acabb569e0d9a23405812a2d58f"},"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/grokify%2Fapp-stores-guide","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/grokify%2Fapp-stores-guide/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/grokify%2Fapp-stores-guide/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/grokify%2Fapp-stores-guide/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/grokify","download_url":"https://codeload.github.com/grokify/app-stores-guide/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":246531986,"owners_count":20792735,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-10-05T00:21:23.955Z","updated_at":"2026-01-11T02:38:57.285Z","avatar_url":"https://github.com/grokify.png","language":null,"funding_links":[],"categories":[],"sub_categories":[],"readme":"# App Store Review Process\n\n1. [Apple](#apple)\n1. [Atlassian](#atlassian)\n1. [HubSpot](#hubspot)\n1. [Salesforce](#salesforce)\n1. [Slack](#slack)\n1. [Zendesk](#zendesk)\n1. [Zoom](#zoom)\n\n## Apple\n\n1. [App Store Review Guidelines](https://developer.apple.com/app-store/review/guidelines/)\n1. [Inside Apple’s team that greenlights iPhone apps for the App Store](https://www.cnbc.com/2019/06/21/how-apples-app-review-process-for-the-app-store-works.html)\n\n## Atlassian\n\n1. [App approval guidelines](https://developer.atlassian.com/platform/marketplace/app-approval-guidelines/)\n\n### Security\n\n\u003e Publish a security statement: Cloud apps require a published security statement to be listed in the Marketplace. Here's the [Cloud Security Statement](https://www.atlassian.com/trust/security/security-practices#continually-improving) as an example.\n\nhttps://developer.atlassian.com/platform/marketplace/app-approval-guidelines/\n\n## HubSpot\n\n1. [Getting certified in the App Marketplace](https://developers.hubspot.com/docs/api/certification-requirements)\n\n### Security\n\n\u003e Asking users to copy and paste HubSpot OAuth authorization codes or account API keys is prohibited. Not only does this add friction to the setup process, it’s a security liability.\n\n## Microsoft\n\n1. [10 app store principles to promote choice, fairness and innovation](https://blogs.microsoft.com/on-the-issues/2020/10/08/app-store-fairness-caf-interoperability-principles/)\n1. [Microsoft hits out at Apple with its new Windows app store policies](https://www.theverge.com/2020/10/8/21507682/microsoft-apple-app-store-policies-principles-list)\n\n## Salesforce\n\n1. [Security Review Overview](https://partners.salesforce.com/s/education/appinnovators/Security_Review)\n1. [What this AppExchange Partner did to Pass Security Review the First Time](https://medium.com/inside-the-salesforce-ecosystem/what-this-appexchange-partner-did-to-pass-security-review-the-first-time-16a0a5cbd1ba)\n1. [How To Pass Salesforce AppExchange Security Review](https://magicforce.co/blog/how-to-pass-salesforce-appexchange-security-review/)\n\n### Security\n\n\u003e How to Prepare for Security Review\n\u003e \n\u003e 1. Complete two Trailhead modules: \n\u003e \n\u003e * [Develop Secure Web Apps \u003e](https://trailhead.salesforce.com/en/content/learn/trails/security_developer)\n\u003e * [AppExchange Security Review \u003e](https://trailhead.salesforce.com/en/content/learn/modules/isv_security_review)\n\u003e \n\u003e 2. Speak to a partner recruitment representative to confirm that your solution is fully enrolled and contracted into the [AppExchange Partner Program \u003e](https://partners.salesforce.com/s/education/appinnovators/AppExchange_Partner_Program)\n\u003e \n\u003e 3. Access the Partner Security Portal to:\n\u003e \n\u003e * Run the static code analysis scanner, Checkmarx, on your Salesforce package components to check for any preliminary vulnerabilities.\n\u003e * Run web app scanners Chimera or ZAP (https://security.secure.force.com/security/tools/webapp/zapbrowsersetup) (a web app scanner if you do not own the external domain) on the external component of your solution. Please note that these scans do not catch everything. You must perform your due diligence in manual testing to ensure secure development.\n\u003e * Book submission-related or technical office hours for security review. \n\u003e \n\u003e 4. Watch the security review wizard walk-through demo below.\n\u003e \n\u003e [Learn more about the security review process in the ISVforce Guide \u003e](https://developer.salesforce.com/docs/atlas.en-us.packagingGuide.meta/packagingGuide/security_review_guidelines.htm)\n\n[Security Review Overview](https://partners.salesforce.com/s/education/appinnovators/Security_Review)\n\n## Slack\n\n1. [Slack App Security Review](https://api.slack.com/security-review)\n\n### Security\n\n\u003e We reserve the right to perform the following on the applicable parts of your application:\n\u003e \n\u003e * Automated web application security scanning\n\u003e * Automated network security scanning\n\u003e * Manual verification of proper authentication scope requests to ensure least-privilege design\n\u003e * Manual testing of functionality for security vulnerabilities and misuse\n\u003e * Manual architecture review of your application\n\u003e * Ask you follow-up questions about functionality\n\n## Zendesk\n\n1. [Publish your app or theme](https://developer.zendesk.com/apps/docs/publish/submit_your_app)\n\n## Zoom\n\n1. [Submission review](https://marketplace.zoom.us/docs/guides/publishing/app-submission/submission-review)\n1. [Security](https://marketplace.zoom.us/docs/guides/publishing/security)\n\n### Security\n\n\u003e Security and compliance review\n\u003e \n\u003e All Zoom Marketplace apps are subject to a security and compliance audit encompassing a multi-part review intended to maintain customer security, integrity and resilience of the ecosystem as a whole.\n\u003e \n\u003e Once you have submitted your app for review, after a successful functional review and prior to the publication of your app on the Zoom App Marketplace, the App Security team at Zoom will conduct a security and compliance review of your app.\n\u003e \n\u003e The App Security team may, in its discretion, communicate with you regarding changes that you might have to make in order for your app to pass the security review; provided, however, that the results of the security review are confidential and may not be shared with third parties without Zoom’s prior written consent. Your app will not be approved on the Zoom App Marketplace unless it passes the security and compliance review. Learn more about our security best practices [here](https://marketplace.zoom.us/docs/guides/publishing/security).\n\u003e \n\u003e ...","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fgrokify%2Fapp-stores-guide","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fgrokify%2Fapp-stores-guide","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fgrokify%2Fapp-stores-guide/lists"}