Skip to content

Security: bitty-terminal/bitty

Security

SECURITY.md

Security Policy

Supported Versions

No version of Bitty has been released. Every listed version is unreleased and no release receives security support yet.

Version Supported
0.0.x No (not released)

Reporting a Vulnerability

Report security vulnerabilities privately through a GitHub Security Advisory.

Do not report security vulnerabilities via public GitHub issues, pull requests, discussions, or chat channels.

When reporting, include as much of the following as possible:

  • Affected repository paths, components, or configuration files
  • Reproduction steps or a proof of concept
  • Expected versus actual behavior
  • Assessment of impact and any known workarounds

Disclosure Policy and Response Expectations

  • Reports are acknowledged and triaged by maintainers, with an initial response targeted within a reasonable timeframe after the advisory is filed.
  • Accepted reports are investigated, fixed, and coordinated with the reporter before any public disclosure.
  • Credit is given to reporters in release notes unless anonymity is requested.
  • The project follows coordinated vulnerability disclosure; details of a vulnerability are published only after a fix or mitigation is available.

This policy describes project process only. It does not describe implemented security controls: the repository is pre-release scaffolding and its P0 security controls are not implemented. Normative security requirements live in the bitty-docs security corpus.

There aren't any published security advisories