Add /.well-known/security.txt (RFC 9116)#2179
Open
kobihikri wants to merge 1 commit into
Open
Conversation
helm.sh serves no security.txt at the well-known location, so a researcher following RFC 9116 has no machine-discoverable pointer to Helm's security reporting channel (the CNCF Helm security list). Added under static/, pointing Contact at that list and Policy at the community SECURITY.md. Signed-off-by: Kobi Hikri <kobi.hikri@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Add
/.well-known/security.txtunderstatic/so helm.sh serves one.Why
https://helm.sh/.well-known/security.txtcurrently returns 404. RFC 9116 makes/.well-known/security.txtthe standard, machine-discoverable place a researcher looks first to find how to report a security issue. Helm already publishes a reporting channel (thecncf-helm-security@lists.cncf.iolist, per the community SECURITY.md); this just makes it discoverable by the RFC convention. The file is served verbatim fromstatic/and carries a futureExpiresper §2.5.5. Signed off per DCO.I used AI assistance to identify this and draft the file; I verified the live 404 and the reporting channel myself.