Security updates and patches are provided for the following versions:
| Version | Supported | Target Runtime | Notes |
|---|---|---|---|
| 2.0.x | ✅ | .NET 8.0, 9.0, 10.0 | Current active production release |
| 1.0.x | ❌ | .NET 8.0, 9.0, 10.0 | Deprecated release — upgrade to v2.0.0 |
| < 1.0.0 | ❌ | — | Pre-release versions not supported |
We take the security of EricksonLopez.ValueObjects seriously. If you discover a security vulnerability, please do NOT open a public GitHub issue.
- Email Notification: Send a detailed description of the vulnerability to ericksonlopezf@gmail.com.
- Details to Include:
- Component / package name and version affected.
- Proof of Concept (PoC) or reproducible test case.
- Potential impact and threat vector.
- Response Timeline:
- Initial Response: Within 48 hours acknowledging receipt.
- Assessment & Fix: Security patches are prioritized and developed privately.
- Public Advisory: A CVE or GitHub Security Advisory will be published once the patch is released.
To ensure maximum supply chain integrity:
- Deterministic Builds: Enabled via
<ContinuousIntegrationBuild>true</ContinuousIntegrationBuild>in CI/CD. - Source Link & Debug Symbols: All packages embed untracked sources and include portable symbol packages (
.snupkg) via SourceLink. - Central Package Management (CPM): Dependencies are strictly pinned and managed centrally in
Directory.Packages.propswith<CentralPackageTransitivePinningEnabled>true</CentralPackageTransitivePinningEnabled>. - Zero Warnings Enforcement: Compiled with
<TreatWarningsAsErrors>true</TreatWarningsAsErrors>and.NET Analyzers (AnalysisLevel=latest-recommended).
- Sensitive Data Protection (PII Defense):
- Types containing Personally Identifiable Information (PII) or credentials (such as
PasswordHash,NationalId,PassportNumber,Cedula,Rnc,Cuit,Rut) are decorated with[SensitiveData]and[DebuggerDisplay]. ToString()automatically redacts the sensitive value (e.g.******or masked digits) to prevent accidental leakage into telemetry, log aggregators, and debugger visualizers.
- Types containing Personally Identifiable Information (PII) or credentials (such as
- Fail-Closed Domain Validation:
- Value Objects enforce private constructors and static
Createfactories returningResult<T>. An unvalidated or malformed instance cannot be instantiated, preventing bypass attacks at runtime.
- Value Objects enforce private constructors and static