ChromaDotNet

Security

This page is about ChromaDotNet.Client and ChromaDotNet.Client.DependencyInjection, the packages the other ChromaDotNet libraries build on. The full policy is in SECURITY.md.

How the packages are published

What every change goes through

What the packages depend on

Verifying a package

The latest GitHub releases have the packages as published on nuget.org, with their Sigstore signatures, made by the release workflow. With Cosign 3 or later:

cosign verify-blob ChromaDotNet.Client.2.10.0.nupkg --bundle ChromaDotNet.Client.2.10.0.nupkg.sigstore.json --certificate-identity-regexp '^https://github.com/ChromaDotNet/ChromaDB.Client/\.github/workflows/release-assets\.yml@' --certificate-oidc-issuer https://token.actions.githubusercontent.com

nuget.org also signs every package with its repository signature:

dotnet nuget verify --all ChromaDotNet.Client.2.10.0.nupkg

Reporting a vulnerability

Do not report a vulnerability in a public issue. Report it privately on GitHub: Report a vulnerability. We acknowledge the report within 7 days, and confirm or rule it out within 14 days. Security fixes go into the latest release.