transparency-exchange-api
transparency-exchange-api copied to clipboard
Using security.txt to indicate TEA service availability
As an alternative, we could register a
security.txtfield.The list of
security.txtfields is also a registry maintained by IANA.
Originally posted by @ppkarwasz in #30
Security.txt is a good way to be able to find the API without having to have a product ID. It's different than the "ordinary" TEA discovery based on the TEI.
From the RFC: "Designated experts should determine whether a proposed registration or update provides value to organizations and researchers using this format and makes sense in the context of industry-accepted vulnerability disclosure processes such as [ISO.29147.2018] and [CERT.CVD]."