From 12c95b07d3fcb88ad0b1312b267aeda762ff2dff Mon Sep 17 00:00:00 2001 From: Kumi Date: Fri, 15 Mar 2024 10:46:36 +0100 Subject: [PATCH] feat(security): add security.txt for reporting issues Introduced a security.txt file to provide a standard way for security researchers to report vulnerabilities. The file specifies contact information, preferred languages, and encryption details for secure communication. This addition aligns with best practices for open-source projects, enhancing our project's security posture. - Establishes a clear communication channel for security issues. - Encourages responsible disclosure by providing encryption options. - Helps to streamline the vulnerability reporting process. This change is in line with the security recommendations for modern web services and applications. --- security.txt | 15 +++++++++++++++ 1 file changed, 15 insertions(+) create mode 100644 security.txt diff --git a/security.txt b/security.txt new file mode 100644 index 0000000..ad45ffc --- /dev/null +++ b/security.txt @@ -0,0 +1,15 @@ +-----BEGIN PGP SIGNED MESSAGE----- +Hash: SHA256 + +Contact: mailto:support@private.coffee +Preferred-Languages: en, de +Encryption: https://security.private.coffee/security@private.coffee.pub +Canonical: https://security.private.coffee/security.txt +Signed by: https://security.private.coffee/security@private.coffee.pub +-----BEGIN PGP SIGNATURE----- + +iI4EARYIADYWIQR8+ffWeJVvJW3sPVIzxXDbF7H3lgUCZfQYvRgcc2VjdXJpdHlA +cHJpdmF0ZS5jb2ZmZWUACgkQM8Vw2xex95ZAUwEA7tZJDZj7E/SLgxMguyKHZ0cg +76oOQSEWzXumiVYlTOgBALQtAPHxGxbOxvDEJ1I8JzSUcYNV9ILx3ugWtM5FuoIN +=e9Q0 +-----END PGP SIGNATURE-----