Security fixes go into the latest release of ChromaDotNet.VectorData on NuGet. Earlier versions do not get fixes: update to the latest one.
Please do not report a vulnerability in a public issue, discussion or pull request.
Report it privately on GitHub instead: Report a vulnerability, in the Security tab of this repository. Only the maintainers see the report.
Include the version of the package, the version of Chroma or Chroma Cloud, and the steps to reproduce the problem.
- We acknowledge the report within 7 days.
- We confirm or rule out the vulnerability within 14 days, and keep you informed of the progress.
- A confirmed vulnerability is fixed in a new release. A GitHub security advisory follows the release, with credit to you unless you prefer otherwise.
- Please keep the details private until the advisory is published, and for at most 90 days from the report.
- Only the CI publishes the package, from the version tags of this repository, with NuGet trusted publishing: no NuGet API key is kept by a person or in the repository.
- The organization requires two-factor authentication.
- The workflows pin their actions to commit hashes. Dependabot and CodeQL check the dependencies and the code.