Skip to content

Security: Digvijay/AutoMappic

SECURITY.md

Security Policy

AutoMappic provides object mapping without runtime reflection. This document describes how to report a vulnerability and what response to expect.

Reporting a vulnerability

Do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.

Report vulnerabilities privately through either of the following channels:

Please include as much of the following as you can provide:

  • The type of issue and the affected component or package
  • Full paths of the source files related to the issue
  • The affected version, commit, or package version
  • Step-by-step instructions to reproduce
  • Proof-of-concept or exploit code, if available
  • The impact of the issue, including how an attacker might exploit it

If this project is transferred to Microsoft

This repository is prepared for review by the Microsoft Open Source Programs Office. If ownership transfers to Microsoft, security reporting moves to the Microsoft Security Response Center (MSRC) and this policy will be replaced by the standard MSRC policy:

Until such a transfer occurs, use the maintainer channels above. Do not send reports for this project to MSRC, because MSRC does not currently own this code.

Response targets

Stage Target
Acknowledgement of report 3 business days
Initial assessment and severity triage 10 business days
Fix or documented mitigation for High/Critical 90 days from triage

These are best-effort targets for an independently maintained project, not a contractual service-level agreement. See SUPPORT.md for the support model.

Supported versions

Security fixes are applied to the latest released minor version. Older versions are not patched. See SUPPORT.md for the full support and lifecycle statement.

Disclosure policy

This project follows coordinated disclosure. Issues are disclosed publicly through a GitHub Security Advisory once a fix or documented mitigation is available. Reporters are credited unless they ask not to be.

Security considerations for users

AutoMappic generates mapping code at compile time. Review generated mappings so that untrusted input DTOs cannot silently overwrite privileged destination members (for example identity, role, or audit fields). Use explicit ignore configuration for sensitive members.

Build-time code generation is part of this project's design. Source generators execute inside the compiler process during build. Only build code you trust, and review generated output when it participates in a security decision.

There aren't any published security advisories