Skip to content

Security: bitty-terminal/bitty-docs

Security

SECURITY.md

Security Policy

Supported Versions

No stable version of Bitty has been released; pre-alpha releases exist but there is no supported release line. All documented behavior is pre-alpha design and implementation material without security-verification claims.

Version Supported
(pre-alpha, unsupported) No

Once a stable release exists, this table will list each supported version range and its support status.

Reporting a Vulnerability

To report a security vulnerability, open a private GitHub Security Advisory.

Do not report security vulnerabilities via public GitHub issues, pull requests, discussions, or chat channels.

When reporting, include as much of the following as applicable:

  • A description of the suspected vulnerability and its impact.
  • The affected document, specification section, or (once they exist) component and version.
  • Steps or inputs needed to reproduce the issue.
  • Any suggested mitigation, if you have one.

Disclosure Policy

  • Reports are handled privately from intake through fix, coordination, and disclosure. Details are not discussed publicly while a fix or mitigation is being prepared.
  • Reporters will receive an acknowledgment and a tracking reference, and will be kept informed of assessment outcomes and resolution timelines.
  • Coordinated disclosure is the default: a public advisory accompanies or follows the release of a fix. Credit for reporters is given by default and may be declined on request.
  • Security requirements for future Bitty implementations live in the canonical security corpus under docs/security/; that corpus takes precedence over historical notes when statements conflict.

Response Expectations

These targets are process commitments for this documentation repository, not claims about shipped product behavior:

  • Acknowledgment of a new report: within 5 business days.
  • Initial severity and impact assessment: within 10 business days of acknowledgment.
  • Fix or mitigation guidance for confirmed issues: targeted within 90 days, sooner for high-severity findings; complex issues receive a communicated timeline instead of silence.

There aren't any published security advisories