Skip to content

Security: AdCodicem/AdCodicem.ValueObjects

SECURITY.md

Security policy

Supported versions

This project has not reached 1.0 yet. Only the most recently published version receives security fixes — while the version number starts with 0., the fix ships in the next release rather than as a patch to an older line.

Reporting a vulnerability

Please do not open a public issue for a security vulnerability.

Use GitHub's private vulnerability reporting instead: https://github.com/AdCodicem/AdCodicem.ValueObjects/security/advisories/new, or the Security tab of this repository → Report a vulnerability. That opens an advisory visible only to the maintainer, which is the fastest way to get a fix moving without disclosing the issue before a patch exists.

Expect an initial response within a few days. If the report is confirmed, the fix is prepared privately and a GitHub Security Advisory is published alongside the patched release, crediting the reporter unless you would rather stay anonymous.

Verifying a release

Every stable release attaches its .nupkg and .snupkg files to the GitHub Release, together with a SLSA build provenance attestation signed through Sigstore. It proves which workflow run, at which commit of this repository, built each file:

gh attestation verify AdCodicem.ValueObjects.<version>.nupkg --repo AdCodicem/AdCodicem.ValueObjects

Verify the files downloaded from the GitHub Release. The copy nuget.org serves carries nuget.org's own repository signature, added after the upload, so its digest no longer matches the attestation. To restrict restores to packages published by this account on nuget.org instead, use dotnet nuget trust repository nuget.org --owners AdCodicem.

Scope

These packages generate code that runs inside a consumer's application and carry no network or process boundary of their own, so the interesting reports tend to be:

  • A generated member that parses attacker-controlled input unsafely — the Parse / TryParse surface, the Pattern regex (including a pattern that makes catastrophic backtracking reachable), or the span-based normalizers.
  • A validation rule that can be bypassed, letting a value object hold a value its declaration forbids. CreateUnchecked is deliberately unchecked and documented as such, so its use by a consumer is not in itself a finding.
  • An integration that lets a value cross a boundary without its rules — the model binder, the EF Core converter, the Dapper handler, or a JSON converter.

A vulnerability in a dependency is better reported upstream; open an issue here only if this repository pins a version that is known to be affected.

There aren't any published security advisories