https://en.wikipedia.org/wiki/Security.txt
Reposted from r/selfhosted.
https://en.wikipedia.org/wiki/Security.txt
Reposted from r/selfhosted.
I do, but with a few tweaks that cut most of the junk the other comments mention:
Contact: at a dedicated alias, not your main inbox, and filter it hard. If the noise gets bad you can drop the alias without touching anything else.Policy: line linking to a short page that says plainly there is no bug bounty and no payment for reports. Most beg-bounty mails are mass-sent with a payment ask, so this gives you something to point them at and lets you bin them without guilt.Expires:, it’s actually required by RFC 9116 and a lot of hand-written files leave it out. Set a calendar reminder to bump it./.well-known/security.txt; the root path is only a legacy fallback.Whether it’s worth it for a homelab is debatable, but if you host anything other people rely on (a Matrix/Lemmy instance, a shared Nextcloud), having one real contact path beats someone finding a hole and having nowhere to send it.
If you run any sort of public facing website, you’ll likely get some of those eventually.

I was gonna say you had it in the wrong place, but it looks like you also serve it in the /.well-known/ location as well.
I have a security.txt with an email to report vulnerabilities and a public key to encrypt sensitive information. The only reports I ever got were on the contract us form, unencrypted.