<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Security on Arkadii Yakovets</title><link>https://arkid15r.dev/categories/security/</link><description>Recent content in Security on Arkadii Yakovets</description><language>en</language><copyright>© Arkadii Yakovets</copyright><lastBuildDate>Sat, 05 Sep 2026 10:00:00 -0700</lastBuildDate><atom:link href="https://arkid15r.dev/categories/security/index.xml" rel="self" type="application/rss+xml"/><item><title>Not as well-known as it should be: shipping security.txt</title><link>https://arkid15r.dev/security-txt-standard/</link><pubDate>Sat, 08 Aug 2026 16:00:00 -0700</pubDate><guid>https://arkid15r.dev/security-txt-standard/</guid><description>security.txt (RFC 9116) is a small, predictable file at /.well-known/security.txt that tells researchers where to report vulnerabilities -- contact, policy, expiry, and related fields. The format is simple and widely referenced, yet adoption is uneven: some flagship sites ship rich signed files, while others omit Expires or skip the file entirely. This post covers the well-known location rules, what good-enough looks like in practice, and a curated look at live examples worth opening in a tab. It also walks through a practical shipping checklist and the file this site now publishes. An update from September 2026 adds a European software-vendor adoption scan to the picture.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://arkid15r.dev/security-txt-standard/feature.jpg"/></item></channel></rss>