Skip to main content
Drupal is a registered trademark of Dries Buytaert
Release: Views Bootstrap 5.5.4 — Minor update available for module views_bootstrap (5.5.4). Release: Rightup theme 1.0.3 — Minor update available for theme vartheme_bs5_rightup (1.0.3). Release: CommentOn 1.0.6 — Minor update available for module commenton (1.0.6). Release: ChatGPT Ads 1.0.3 — Minor update available for module chatgpt_ads (1.0.3). Release: Opensolr Search 5.1.3 — Minor update available for module opensolr_search (5.1.3). Release: ServiceM8 Webform Integration 1.2.1 — Minor update available for module servicem8_webform (1.2.1). Release: PostfixAdmin 1.0.0 — Initial release available for module postfix_admin (1.0.0)! Release: ip_analyser 1.0.3 — Minor update available for module ip_analyser (1.0.3). Module Revived: Swagger-PHP OpenAPI 3 documentation generator 1.0.0 — Module swagger_php updated after 10 months of inactivity (1.0.0). Security Coverage: Microsoft Azure AI — Module ai_provider_azure now has official Drupal security advisory coverage.

A module which allows a drupal site to serve a security.txt file and provides a friendly administration user interface.

Introduction

The Security.txt module provides an implementation of the security.txt standard which is currently a draft RFC. Its purpose is to provide a standardized way to document your website’s security contact details and policy. This allows users and security researchers to securely disclose security vulnerabilities to you.

Installation

This module should be installed in the usual way, see installing modules.

Configuration

Once you have installed this module you will want to perform the
following configuration.

Permissions

You control the permissions granted to each role at /admin/people/permissions. You will almost certainly want to give everyone the 'View security.txt' permission, i.e. give it to both the 'Anonymous User and 'Authenticated User' roles.

You will only want to give the 'Administer security.txt' permission to very trusted roles.

Security.txt configuration

The Security.txt module configuration page can be found under 'System' on the Drupal configuration page. Fill in all the details you want to add to your security.txt file, then press the 'Save configuration' button. You should then proceed to the 'Sign' tab of the configuration form.

Security.txt signing

You can provide a digital signature for your security.txt file by following the instructions on the 'Sign' tab of the module’s configuration page.

Use

Once you have completed the configuration of the Security.txt module your security.txt and security.txt.sig files will be available at the following standard URLs:

  • /.well-known/security.txt
  • /.well-known/security.txt.sig

Backdrop Port

There is a backdrop port of this module.

Further reading

Depends on

Dependencies of the latest stable release

No dependencies recorded for this project.

Required by

Tracked projects that depend on this one

No tracked projects depend on this one yet.

Activity

Tracked releases
4
Tracked since
Jun 2023
Latest release
2 years ago
Releases (12 mo)
0
Maintenance
Dormant

Release Timeline

Releases

Version Type Core Release date
8.x-1.6 Stable May 16, 2024
8.x-1.5 Stable May 16, 2024
8.x-1.4 Stable Aug 9, 2023
8.x-1.3 Stable Jun 1, 2023