# Vulnerability disclosure — RFC 9116 # # Placeholder values below are marked. Replace them at deploy time from the # same configuration that supplies every other association contact; do not # hardcode an address here. # # A security.txt pointing at an unmonitored inbox is worse than none. A # researcher who receives no reply publishes instead, and the first the # association hears of the finding is from a journalist. Contact: mailto:REPLACE_WITH_PRIMARY_CONTACTS_SECURITY Expires: 2027-08-17T00:00:00.000Z Preferred-Languages: en Canonical: https://REPLACE_WITH_PUBLIC_DOMAIN/.well-known/security.txt Policy: https://REPLACE_WITH_PUBLIC_DOMAIN/security