https://en.wikipedia.org/wiki/Security.txt

Reposted from r/selfhosted.

you are viewing a single comment's thread
view the rest of the comments
[–] 4 points 11 hours ago

I do, but with a few tweaks that cut most of the junk the other comments mention:

  • Point Contact: at a dedicated alias, not your main inbox, and filter it hard. If the noise gets bad you can drop the alias without touching anything else.
  • Add a Policy: line linking to a short page that says plainly there is no bug bounty and no payment for reports. Most beg-bounty mails are mass-sent with a payment ask, so this gives you something to point them at and lets you bin them without guilt.
  • Don't forget Expires:, it's actually required by RFC 9116 and a lot of hand-written files leave it out. Set a calendar reminder to bump it.
  • Serve it at /.well-known/security.txt; the root path is only a legacy fallback.

Whether it's worth it for a homelab is debatable, but if you host anything other people rely on (a Matrix/Lemmy instance, a shared Nextcloud), having one real contact path beats someone finding a hole and having nowhere to send it.

  • source