Security
This page is about ChromaDotNet.Client and ChromaDotNet.Client.DependencyInjection, the packages the other ChromaDotNet libraries build on. The full policy is in SECURITY.md.
How the packages are published
- Only the CI publishes the packages, from the version tags of ChromaDotNet/ChromaDB.Client, with NuGet trusted publishing. No person and no repository keeps a NuGet API key.
- The
ChromaDotNet.*prefix is reserved on nuget.org for this organization. - The organization requires two-factor authentication.
What every change goes through
maintakes changes only through pull requests, and only when these checks pass: the tests on nine Chroma versions from 0.4.10 to 1.5.9, the trimming and NativeAOT build, the .NET Framework build, and CodeQL. The rule has no exceptions.- The workflows pin their actions to commit hashes.
- Dependabot watches the dependencies and the actions, and OpenSSF Scorecard rates the repository.
What the packages depend on
ChromaDotNet.Client: System.Text.Json, System.Diagnostics.DiagnosticSource and System.Memory, all from Microsoft.ChromaDotNet.Client.DependencyInjection: the client, Microsoft.Extensions.DependencyInjection.Abstractions and Microsoft.Extensions.Http.
Verifying a package
The latest GitHub releases have the packages as published on nuget.org, with their Sigstore signatures, made by the release workflow. With Cosign 3 or later:
cosign verify-blob ChromaDotNet.Client.2.10.0.nupkg --bundle ChromaDotNet.Client.2.10.0.nupkg.sigstore.json --certificate-identity-regexp '^https://github.com/ChromaDotNet/ChromaDB.Client/\.github/workflows/release-assets\.yml@' --certificate-oidc-issuer https://token.actions.githubusercontent.com
nuget.org also signs every package with its repository signature:
dotnet nuget verify --all ChromaDotNet.Client.2.10.0.nupkg
Reporting a vulnerability
Do not report a vulnerability in a public issue. Report it privately on GitHub: Report a vulnerability. We acknowledge the report within 7 days, and confirm or rule it out within 14 days. Security fixes go into the latest release.