Flowpane / Docs

Common security.txt issues

Expires field missing

RFC 9116 requires exactly one. Add an authored future RFC 3339 date-time; the Workbench may offer a bounded date-only patch, but review the policy owner and signing workflow.

Expires date has passed

Publish a newly reviewed future RFC 3339 value.

Wrong location

Should be at /.well-known/security.txt, not /security.txt.

Canonical not set

Canonical is optional. Add it only after confirming the exact deployed retrieval URI; Flowpane does not invent that authority.

Clear-signed file changed

Any changed Proposed payload is unsigned and must be signed again before publication. Flowpane preserves signature evidence but does not perform OpenPGP cryptographic verification.