Skip to content

Security: Sarmkadan/dotnet-outbox-pattern

Security

SECURITY.md

1 # Security Policy 2 3 ## Reporting a Vulnerability 4 5 The .NET Outbox Pattern project takes security seriously. We appreciate your efforts to responsibly disclose security vulnerabilities to us. 6 7 ### DO NOT Open Public Issues for Security Vulnerabilities 8 9 Please do not open a GitHub issue to report security vulnerabilities. Public issues can expose security risks to bad actors. Instead, use the procedures below. 10 11 ## Responsible Disclosure 12 13 ### Option 1: GitHub Private Vulnerability Reporting (Recommended) 14 15 GitHub provides a secure way to report vulnerabilities privately: 16 17 1. Visit: https://github.com/sarmkadan/dotnet-outbox-pattern/security/advisories/new 18 2. Use the GitHub interface to report the vulnerability 19 3. Your report will be visible only to the maintainers 20 21 ### Option 2: Email 22 23 If you prefer email, send vulnerability details to: 24 25 26 rutova2@gmail.com 27 28 29 Include: 30 - Description of the vulnerability 31 - Steps to reproduce (if applicable) 32 - Potential impact 33 - Suggested fix (if you have one) 34 - Your name and contact information (optional) 35 36 ## Response Timeline 37 38 We are committed to addressing security vulnerabilities promptly: 39 40 - Acknowledgment: We will acknowledge receipt of your report within 48 hours 41 - Assessment: We will assess the vulnerability within 1 week 42 - Fix: We will work on a fix and coordinate a responsible disclosure timeline with you 43 - Publication: Once fixed, we will publish a security advisory 44 45 ## Supported Versions 46 47 Security updates are provided for: 48 49 | Version | Supported | 50 |---------|-----------| 51 | 2.0.x | Yes | 52 | 1.x | Security fixes only | 53 54 Only the latest version receives security updates. We recommend upgrading to the latest version to receive all security patches. 55 56 ## Types of Vulnerabilities We Prioritize 57 58 We prioritize fixes for: 59 60 - Authentication & Authorization: Issues that could allow unauthorized access 61 - Data Exposure: Vulnerabilities that could leak sensitive data 62 - Code Injection: SQL injection, command injection, code injection attacks 63 - Cryptography: Weak encryption, insecure algorithms 64 - Input Validation: Issues with message/payload validation 65 - Dependency Vulnerabilities: Known vulnerabilities in third-party packages 66 67 ## Security Best Practices for Users 68 69 When using the .NET Outbox Pattern in production: 70 71 1. Keep Dependencies Updated: Regularly update NuGet packages 72 bash 73 dotnet outdated 74 dotnet package update 75 76 77 2. Use HTTPS: Always use HTTPS in production environments 78 79 3. Database Security: 80 - Use strong credentials 81 - Restrict database access to only required services 82 - Enable encryption at rest and in transit 83 - Use parameterized queries (already enforced in this library) 84 85 4. Configuration: 86 - Never hardcode secrets 87 - Use environment variables or secure configuration managers 88 - Rotate credentials regularly 89 - Audit configuration changes 90 91 5. Monitoring: 92 - Monitor for failed message deliveries 93 - Set up alerts for dead letter queue growth 94 - Review logs regularly for suspicious activity 95 - Track message latency and throughput 96 97 6. Access Control: 98 - Restrict API endpoints to authorized consumers 99 - Implement rate limiting 100 - Use API keys or tokens for authentication 101 - Log all access attempts 102 103 ## Known Issues 104 105 There are currently no known unpatched security vulnerabilities in the .NET Outbox Pattern. 106 107 ## Security Contact 108 109 For all security-related inquiries, use the channels listed in the "Reporting a Vulnerability" section above. 110 111 ## Acknowledgments 112 113 We thank all researchers and users who report security vulnerabilities responsibly, helping us keep this project secure for everyone. 114 115 ## Additional Resources 116 117 - OWASP Top 10 118 - GitHub Security Advisory 119 - Microsoft .NET Security Best Practices 120 121 ## [2.0.1] - (date a week after v2.0.0) 122 ### Security 123 - Added input validation and length limits 124 - Added request timeout configuration 125 - Added security policy and vulnerability reporting 126 127 ## [2.0.0] - 2026-03-17 128 129 ### Security 130 - Runtime container no longer runs as root 131 - Reduced attack surface with --no-install-recommends in apt-get 132 133 ## [0.3.0] - 2025-03-17 134 135 ### Security 136 - Input validation added to all API endpoints 137 - Query parameter length limits enforced 138 - Rate limiting middleware applied globally 139 - Error messages sanitized to avoid leaking internal details 140 141 ## [0.2.0] - 2025-02-24 142 143 ### Security 144 - IMessagePublisher abstraction for pluggable broker implementations 145 - Default console publisher for local development and testing 146 - Entity Framework Core integration with SQL Server 147 - Initial database schema with EF Core migrations 148 - Strongly-typed OutboxConfiguration options class 149 150 ## [0.1.0] - 2025-02-03 151 152 ### Security 153 - Initial project structure targeting .NET 10.0 154 - Core OutboxMessage domain model with state machine 155 - IOutboxService interface and OutboxService implementation 156 - SQL Server data access layer via OutboxRepository 157 - OutboxProcessor hosted service for background message polling 158 - Idempotency key support to prevent duplicate delivery 159 - Structured logging with Serilog 160 - Basic REST API for publishing events 161 - Swagger/OpenAPI documentation 162 - appsettings.json configuration scaffolding 163 - MIT License 164 165 --- 166 167 ## Upgrade Guide 168 168 ### From 0.x to 1.0 169 170 1. Update package references to 1.0.0 171 2. Run database migrations: dotnet ef database update 172 3. Update configuration to use the new strongly-typed options 173 4. Implement a custom IMessagePublisher for your message broker 174 5. Review examples for idempotent subscriber patterns 175 176 --- 177 178 ## Support 179 180 - Report bugs: https://github.com/sarmkadan/dotnet-outbox-pattern/issues 181 - Ask questions: https://github.com/sarmkadan/dotnet-outbox-pattern/discussions 182 - Security issues: security@sarmkadan.com 183 184 ## Types of Vulnerabilities We Prioritize 185 186 We prioritize fixes for: 187 188 - Authentication & Authorization: Issues that could allow unauthorized access 189 - Data Exposure: Vulnerabilities that could leak sensitive data 190 - Code Injection: SQL injection, command injection, code injection attacks 191 - Cryptography: Weak encryption, insecure algorithms 192 - Input Validation: Issues with message/payload validation 193 - Dependency Vulnerabilities: Known vulnerabilities in third-party packages 194 195 ## Security Best Practices for Users 196 197 When using the .NET Outbox Pattern in production: 198 199 1. Keep Dependencies Updated: Regularly update NuGet packages 200 bash 201 dotnet outdated 202 dotnet package update 203 204 205 2. Use HTTPS: Always use HTTPS in production environments 206 207 3. Database Security: 208 - Use strong credentials 209 - Restrict database access to only required services 210 - Enable encryption at rest and in transit 211 - Use parameterized queries (already enforced in this library) 212 213 4. Configuration: 214 - Never hardcode secrets 215 - Use environment variables or secure configuration managers 216 - Rotate credentials regularly 217 - Audit configuration changes 218 219 5. Monitoring: 220 - Monitor for failed message deliveries 221 - Set up alerts for dead letter queue growth 222 - Review logs regularly for suspicious activity 223 - Track message latency and throughput 224 225 6. Access Control: 226 - Restrict API endpoints to authorized consumers 227 - Implement rate limiting 228 - Use API keys or tokens for authentication 229 - Log all access attempts 230 231 ## Known Issues 232 233 There are currently no known unpatched security vulnerabilities in the .NET Outbox Pattern. 234 235 ## Security Contact 236 237 For all security-related inquiries, use the channels listed in the "Reporting a Vulnerability" section above. 238 239 ## Acknowledgments 240 241 We thank all researchers and users who report security vulnerabilities responsibly, helping us keep this project secure for everyone. 242 243 ## Additional Resources 244 245 - OWASP Top 10 246 - GitHub Security Advisory 247 - Microsoft .NET Security Best Practices 248 249 ## [2.0.1] - (date a week after v2.0.0) 250 ### Security 251 - Added input validation and length limits 252 - Added request timeout configuration 253 - Added security policy and vulnerability reporting

There aren't any published security advisories