This website has no released version yet. Until a first release is published, no version is supported and there is no supported release channel.
| Version | Supported |
|---|---|
| (none released) | No |
To report a security vulnerability, open a private GitHub Security Advisory.
Do not report security vulnerabilities via public GitHub issues.
Include what you observed, how to reproduce it, affected URLs or files, and any impact you can demonstrate. Keep proof-of-concept material minimal.
- Reports are handled privately from first contact until a fix or mitigation is available.
- Reporters receive an initial assessment and, when a report is accepted, a rough remediation plan within 5 business days of acknowledgment.
- Fixes are coordinated with the reporter before public disclosure. Public disclosure happens through release notes and, where warranted, a published advisory after affected versions are patched or removed.
- Reporters may request anonymity or credit in disclosures.
The project is pre-implementation. Deployment, publication, analytics, forms, and external service integrations do not exist yet; reports about such non-existent behavior are out of scope. Security requirements for future behavior are defined canonically in the Bitty security documentation and apply before any such behavior ships.