Skip to main content
addly

A security advisory must describe exposure before offering reassurance.

No addly product is published, so the product-advisory register is not yet applicable. This surface defines a format that separates vulnerability, service incident, and functional limitation.

Register state

Not applicable before publication

This does not mean ‘no vulnerabilities’. It means no versioned product is distributed.

The contract of a publishable advisory.

Every future advisory will retain a date, product scope, and verifiable action.

Identity

Identifier, date, author, and revision history.

Affected products

App, hosting, versions, and affected configurations.

Exposure

Exploitation condition, data, or permissions involved.

Observed impact

Observable consequence without marketing minimization.

Mitigation

Temporary action, side effects, and verification.

Resolution

Fixed version, changelog, documentation, and workaround removal.

Three registers, three responsibilities.

  1. 01Product vulnerabilityVersion, exposure, mitigation, and fix.Advisory
  2. 02Service incidentAvailability, timeline, recovery, and retrospective.Status
  3. 03Functional limitationBehavior, scope, workaround, and documentation.Limitations

‘No advisories’ is never evidence of security.

Before launch, connect a private channel, triage procedure, and owner who can publish this register without marketing delay.