@bagderdaniel:// stenberg:// IANA just published a new field for the security.txt (RFC 9116) format: "Bug-Bounty: True/False".

The @RIOT_OSRIOT team is receiving an increased amount of presumably LLM generated bogus vuln reports (though nowhere near curl levels). And since we deployed a security.txt, scrapers started sending emails inquiring about our bug bounty programs.

I was hoping that if that field gets some visibility, scrapers might filter for that before spamming the security inboxes.

iana.org/assignments/security-

0

If you have a fediverse account, you can quote this note from your own instance. Search https://toot.community/users/maribu/statuses/116194191111006496 on your instance and quote it. (Note that quoting is not supported in Mastodon.)