proudcity / wp-proudcity

The ProudCity WordPress platform
https://proudcity.com
Other
21 stars 9 forks source link

Add security.txt #2618

Closed lukefretwell closed 1 month ago

lukefretwell commented 1 month ago

Source

The source of the issue (ex: Customer: #CustomerName#).

LF

Feedback

A member of a state digital service team shared info about the security.txt practice we should consider.

Note: Note sure we can insert the canonical dynamically, but would be awesome of we could.

File contents:

Contact: https://proudcity.com/report-vulnerability
Canonical: https://www.URL/.well-known/security.txt
Expires: 2030-01-01T20:00:00.000Z
Preferred-Languages: en

Reference:

QA

Notes:

Links:

*

lukefretwell commented 1 month ago

@curtismchale @kevindherman reading over Krebs' post on this, there's a good chance this may be deluged with emails, so suggest we accept that for security or create a new security-txt@ group.

https://krebsonsecurity.com/2021/09/does-your-organization-have-a-security-txt-file/

lukefretwell commented 1 month ago

Created a page instead: https://proudcity.com/report-vulnerability

curtismchale commented 1 month ago

Deployed with #2619