Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add /.well-known/security.txt #11258

Open
github-throwaway opened this issue Jan 17, 2025 · 0 comments
Open

Add /.well-known/security.txt #11258

github-throwaway opened this issue Jan 17, 2025 · 0 comments

Comments

@github-throwaway
Copy link
Contributor

github-throwaway commented Jan 17, 2025

A security.txt file serves as a standardized method for organizations to specify their vulnerability disclosure policies. By placing this file in a well-known location, security researchers can easily identify the appropriate channels to report potential security issues. This proactive approach not only streamlines the reporting process but also demonstrates a commitment to security best practices.

https://securitytxt.org/

What fields should be populated? Probably just the email I suppose? Here is Googles version:

Contact: https://g.co/vulnz
Contact: mailto:[email protected]
Encryption: https://services.google.com/corporate/publickey.txt
Acknowledgments: https://bughunters.google.com/
Policy: https://g.co/vrp
Hiring: https://g.co/SecurityPrivacyEngJobs
Expires: 2025-04-01T00:00:00z
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Status: To discuss and validate
Development

No branches or pull requests

1 participant