Closed lukefretwell closed 1 month ago
@curtismchale @kevindherman reading over Krebs' post on this, there's a good chance this may be deluged with emails, so suggest we accept that for security or create a new security-txt@ group.
https://krebsonsecurity.com/2021/09/does-your-organization-have-a-security-txt-file/
Created a page instead: https://proudcity.com/report-vulnerability
Deployed with #2619
Source
The source of the issue (ex: Customer: #CustomerName#).
LF
Feedback
A member of a state digital service team shared info about the
security.txt
practice we should consider.Note: Note sure we can insert the canonical dynamically, but would be awesome of we could.
File contents:
Reference:
https://proudcity.com/security.txt
orhttps://proudcity.com/.well-known/security.txt
(if the latter, would be good to redirect top-levelsecurity.txt
to.well-known
QA
Notes:
Links:
*