Repository navigation
Make security.txt readable by RFC 9116 tooling - #17391
Merged
Merged
Conversation
The file at https://www.mozilla.org/.well-known/security.txt predates RFC 9116 and uses field names the RFC does not define - Email, Main info, Bounty program. A conforming parser therefore finds no Contact field and no Expires field, which are the two the RFC makes mandatory, and treats the file as invalid. In practice that means an automated vulnerability-reporting pipeline looking up where to report a bug in a Mozilla property finds nothing, even though the address is right there in the file. Same three pieces of information, in the field names the RFC defines: the address becomes Contact, the bug bounty page becomes Policy, and the overview page stays as a comment. Expires is dated a year out, the upper bound section 2.5.5 recommends. Canonical is added so a copy found elsewhere can be checked against this one. Checked with well-known-audit against the file as published: before: 2 blockers - no Contact field, no Expires field after: 0 blockers, 0 warnings
mozfreddyb
suggested changes
Sep 21, 2026
mozfreddyb
left a comment
Contributor
There was a problem hiding this comment.
I don't think we want to revisit the file every year. Ideally, we would just leave the Expiry but that's in violation of the RFC.
Let's do +10 years. I also don't think there's a lot of value in having some automated updater here. That just seems like more work than necessary
Contributor
|
Thanks for the pull request. Please change the date to give us additional 10 years before this expires and then it's ready to go. @mozilla/bedrock-team No need to flag security again for a review, once this suggested change is applied. |
Co-authored-by: Frederik Braun <fbraun+gh@mozilla.com>
stevejalim
approved these changes
Sep 21, 2026
Contributor
|
Thanks for the contribution @dkautomation23! I hope this helps improve the stats on https://dkautomation23.github.io/security-txt-survey.html - nice work! |
stevejalim
added a commit
to mozmeao/springfield
that referenced
this pull request
Sep 21, 2026
Port of mozilla/bedrock#17391. The file used field names RFC 9116 does not define (Email, Main info, Bounty program), so conforming parsers saw no Contact or Expires and treated it as invalid. Same three pieces of information, in the RFC's field names, plus Expires, Preferred-Languages and a Canonical URL pointing at www.firefox.com.
bluewave41
pushed a commit
to mozmeao/springfield
that referenced
this pull request
Sep 22, 2026
Port of mozilla/bedrock#17391. The file used field names RFC 9116 does not define (Email, Main info, Bounty program), so conforming parsers saw no Contact or Expires and treated it as invalid. Same three pieces of information, in the RFC's field names, plus Expires, Preferred-Languages and a Canonical URL pointing at www.firefox.com.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The file served at https://www.mozilla.org/.well-known/security.txt predates RFC 9116 and uses field names the RFC does not define —
Email,Main info,Bounty program.A conforming parser reads no
Contactand noExpiresfrom it — the two fields the RFC makes mandatory — and treats the file as invalid. In practice an automated pipeline looking up where to report a vulnerability in a Mozilla property finds nothing, even though the address is in the file.This keeps the same three pieces of information, in the field names the RFC defines:
Contact:(as amailto:URI, which §2.5.3 requires)Policy:Expires:is added, dated a year out (§2.5.5's recommended upper bound)Canonical:is added so a copy found elsewhere can be checked against this oneVerified against the file as currently published:
Two things for you to decide: the
Expiresdate (placeholder a year out — set it to your renewal cadence), and whether to keep the human-readable lines as comments (done here) or drop them.