Common security.txt issues
Expires field missing
RFC 9116 requires exactly one. Add an authored future RFC 3339 date-time; the Workbench may offer a bounded date-only patch, but review the policy owner and signing workflow.
Expires date has passed
Publish a newly reviewed future RFC 3339 value.
Wrong location
Should be at /.well-known/security.txt, not /security.txt.
Canonical not set
Canonical is optional. Add it only after confirming the exact deployed retrieval URI; Flowpane does not invent that authority.
Clear-signed file changed
Any changed Proposed payload is unsigned and must be signed again before publication. Flowpane preserves signature evidence but does not perform OpenPGP cryptographic verification.