Identity
Identifier, date, author, and revision history.
No addly product is published, so the product-advisory register is not yet applicable. This surface defines a format that separates vulnerability, service incident, and functional limitation.
Register state
This does not mean ‘no vulnerabilities’. It means no versioned product is distributed.
Every future advisory will retain a date, product scope, and verifiable action.
Identifier, date, author, and revision history.
App, hosting, versions, and affected configurations.
Exploitation condition, data, or permissions involved.
Observable consequence without marketing minimization.
Temporary action, side effects, and verification.
Fixed version, changelog, documentation, and workaround removal.
Before launch, connect a private channel, triage procedure, and owner who can publish this register without marketing delay.