| Version | Supported |
|---|---|
| 1.0.x | ✅ |
If you discover a security vulnerability, please do not open a public issue.
Instead, email ericksonlopezf@gmail.com with:
- Description of the vulnerability
- Steps to reproduce (or a proof-of-concept)
- Impact assessment — what an attacker could achieve
- Suggested fix (optional)
- Acknowledgement within 48 hours
- Resolution target within 14 days for critical issues
- Credit in the release notes (unless you prefer to remain anonymous)
This policy covers the EricksonLopez.DapperExtensions.PostgreSQL NuGet package and its source code. For vulnerabilities in dependencies (Dapper, Npgsql), please report to their respective maintainers.