-
-
Notifications
You must be signed in to change notification settings - Fork 1k
Add .well-known/security.txt file #2062
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,27 @@ | ||
{% spaceless %} | ||
{% comment %} | ||
This file is served under the well-known URIs | ||
|
||
- https://www.djangoproject.com/.well-known/security.txt | ||
- https://docs.djangoproject.com/.well-known/security.txt | ||
|
||
See https://securitytxt.org/ for more information about the security.txt standard. | ||
{% endcomment %} | ||
{% endspaceless %}# Hello security researcher! | ||
# We appreciate your help in keeping Django & djangoproject.com secure. | ||
|
||
# Please report security issues that concern this website (djangoproject.com) | ||
# to the website working group: website-wg@djangoproject.com | ||
# This helps us make sure your report is directed to the right people. | ||
# You can find guidelines for reporting website security issues here: https://github.com/django/djangoproject.com/blob/main/.github/SECURITY.md | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Note: this url doesn't exist yet. Assumes #2086 is merged. |
||
|
||
# DO NOT USE security@djangoproject.com FOR ISSUES THAT CONCERN THE WEBSITE. | ||
|
||
# If your report concerns Django itself (the Python package, not this website), please follow the Django security reporting process: | ||
Policy: https://www.djangoproject.com/security/ | ||
Contact: https://www.djangoproject.com/security/ | ||
Expires: 2026-12-31T00:00:00.000Z | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Should we separate this line and the content below it from the rest of the file? I initially though that the |
||
Preferred-Languages: en | ||
|
||
# If you would like to encrypt your report, you can use the following PGP key: | ||
Encryption: https://keys.openpgp.org/vks/v1/by-fingerprint/AF3516D27D0621171E0CCE25FCB84B8D1D17F80B |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Do we need it on code.djangoproject.com and/or other subdomains?