security.txt 產生器

依照 RFC 9116 標準產生用於弱點揭露的 security.txt 檔案

所有處理皆在瀏覽器中完成,不會上傳任何資料。
Offline Ready

security.txt 產生器

依照 RFC 9116 標準產生用於弱點揭露的 security.txt 檔案

🔒所有處理皆在瀏覽器中完成,不會上傳任何資料。
聯絡方式
必填

用於回報安全弱點的 URI。必須使用 mailto:、https:// 或 tel: 配置。至少需要一個 Contact 欄位。

mailto:security@example.com
到期日
必填

此 security.txt 資料應視為過時的日期和時間。RFC 9116 規定為必填。建議:不超過一年。

YYYY-MM-DD
加密
選填

指向加密金鑰的 URI,用於安全通訊。必須使用 https://、dns: 或 openpgp4fpr: 配置。

https://example.com/.well-known/pgp-key.txt
致謝
選填

列出負責任回報弱點的安全研究人員的頁面 URI。

https://example.com/hall-of-fame
正式位址
選填

此 security.txt 檔案所在的正式 URI。有助於驗證真實性。

https://example.com/.well-known/security.txt
政策
選填

組織弱點揭露政策的 URI。

https://example.com/security-policy
偏好語言
選填

安全報告偏好語言代碼的逗號分隔清單(ISO 639)。

招聘
選填

組織安全相關職位的 URI。

https://example.com/careers
選項
包含說明性註解
驗證
產生的 security.txt
將此檔案放置於:/.well-known/security.txt
# This is a security.txt file that follows the RFC 9116 standard.
# https://www.rfc-editor.org/rfc/rfc9116

Contact: mailto:security@example.com
Preferred-Languages: en