Skip to content

Consider making security.txt use mandatory for CNAs/projects covered by CNAs #53

Description

@kurtseifried

https://securitytxt.org/

TL;DR: security.txt for reporting security issues, like robots.txt for telling web robots how to behave.

Example file:

# Our security address
Contact: security@example.com
# Our PGP key
Encryption: https://example.com/pgp-key.txt

This would make it much easier for people to discover how to report things (99% of the time you can plug a product name in and get the web page no problem, then the problem becomes finding the contact details for reporting your security vulnerability).

Emailing board as well to start discussion.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions