Django: serve a security.txt file 0 ▲ Adam Johnson 1 hour ago · 7 min read1328 words · Tech · hide · 0 comments When a security researcher finds a vulnerability in your site, they need a way to tell you about it. Without a clear contact, they may resort to guessing at addresses like security@<yourdomain>, messaging random folks on social media, or give up. And of course, in the worst case, they might just publish the details, leaving you to find out when attackers do. security.txt is a web standard to fix this problem. It’s a small text file, served at the reserved path /.well-known/security.txt, that says how to report security issues to your organization. It was standardized in April 2022 as RFC 9116. In this post, we’ll look at serving a security.txt file and adding unit tests and a system check to keep it current. Write the file A security.txt file contains a series of Field: value lines, plus optional comments starting with #. Here’s an example: # Security contact information for example.com Contact: mailto:security@example.com Expires: 2027-09-01T00:00:00Z Preferred-Languages: en… No comments yet. Log in to reply on the Fediverse. Comments will appear here.