# security.txt — RFC 9116. Customer fills in and serves at
# https://<domain>/.well-known/security.txt
# Fill these in by hand. `project new` scaffolds `security_contact` and `disclosure_url`
# into openmv-ota.toml as COMMENTED examples, but nothing reads them yet -- no build step
# pre-fills this file. (An earlier version of this note claimed otherwise.)

Contact: mailto:{{SECURITY_CONTACT_EMAIL}}
Expires: {{EXPIRES_ISO8601}}
Encryption: {{PGP_KEY_URL}}
Policy: {{VULN_DISCLOSURE_POLICY_URL}}
Acknowledgments: {{ACKNOWLEDGMENTS_URL}}
Preferred-Languages: en
Canonical: https://{{DOMAIN}}/.well-known/security.txt
