Skip to content

Consider making security.txt use mandatory for CNAs/projects covered by CNAs #53

Open
@kurtseifried

Description

@kurtseifried

https://securitytxt.org/

TL;DR: security.txt for reporting security issues, like robots.txt for telling web robots how to behave.

Example file:

# Our security address
Contact: [email protected]
# Our PGP key
Encryption: https://example.com/pgp-key.txt

This would make it much easier for people to discover how to report things (99% of the time you can plug a product name in and get the web page no problem, then the problem becomes finding the contact details for reporting your security vulnerability).

Emailing board as well to start discussion.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions