No version of Bitty has been released. Every listed version is unreleased and no release receives security support yet.
| Version | Supported |
|---|---|
| 0.0.x | No (not released) |
Report security vulnerabilities privately through a GitHub Security Advisory.
Do not report security vulnerabilities via public GitHub issues, pull requests, discussions, or chat channels.
When reporting, include as much of the following as possible:
- Affected repository paths, components, or configuration files
- Reproduction steps or a proof of concept
- Expected versus actual behavior
- Assessment of impact and any known workarounds
- Reports are acknowledged and triaged by maintainers, with an initial response targeted within a reasonable timeframe after the advisory is filed.
- Accepted reports are investigated, fixed, and coordinated with the reporter before any public disclosure.
- Credit is given to reporters in release notes unless anonymity is requested.
- The project follows coordinated vulnerability disclosure; details of a vulnerability are published only after a fix or mitigation is available.
This policy describes project process only. It does not describe implemented security controls: the repository is pre-release scaffolding and its P0 security controls are not implemented. Normative security requirements live in the bitty-docs security corpus.