<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>RFC 9116 on Nalar</title>
    <link>https://nalar.dev/tags/rfc-9116/</link>
    <description>Recent content in RFC 9116 on Nalar</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Thu, 24 Sep 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://nalar.dev/tags/rfc-9116/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>security.txt Publishes a Bounded Vulnerability Reporting Route</title>
      <link>https://nalar.dev/security-txt-publishes-a-bounded-vulnerability-reporting-route/</link>
      <pubDate>Thu, 24 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://nalar.dev/security-txt-publishes-a-bounded-vulnerability-reporting-route/</guid>
      <description>&lt;p&gt;A security flaw can be difficult to report even when the affected service is easy to identify. A generic support form may route the message to the wrong queue, an old security mailbox may no longer be staffed, and a researcher cannot safely infer disclosure policy from a company name alone. RFC 9116 addresses that routing problem with &lt;code&gt;security.txt&lt;/code&gt;, a small machine-parsable file published by the service operator.&lt;/p&gt;&#xA;&lt;p&gt;The file does not certify that a service is secure, authorize testing, or define a complete vulnerability disclosure program. Its narrower job is to publish current reporting coordinates and related metadata at a predictable location.&lt;/p&gt;</description>
    </item>
    <item>
      <title>security.txt Publishes a Machine-Readable Vulnerability Contact</title>
      <link>https://nalar.dev/security-txt-publishes-a-machine-readable-vulnerability-contact/</link>
      <pubDate>Thu, 24 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://nalar.dev/security-txt-publishes-a-machine-readable-vulnerability-contact/</guid>
      <description>&lt;p&gt;A vulnerability report can lose value before triage begins if the reporter cannot identify a current, organization-controlled contact. RFC 9116 addresses that routing problem with &lt;code&gt;security.txt&lt;/code&gt;, a machine-parsable text file published at a predictable HTTPS location.&lt;/p&gt;&#xA;&lt;p&gt;The file does not grant testing permission, establish a bug bounty, or prove that a listed recipient is trustworthy. Its narrower role is to publish vulnerability disclosure metadata in a format that people and automated tools can retrieve consistently.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
