Create a public security.txt page so cPanel's security@cpanel.net email address is easier to find
Needs Review
Many companies provide a security.txt page at domain.com/.well-known/security.txt that provides information on who to contact in the event a security issue is found. While cPanel does provide the "security@cpanel.net" email address, that is not well known to all users.
Providing a page at cpanel.net/.well-known/security.txt would make this information public and accessible.
You can see an example of this at https://www.google.com/.well-known/security.txt, which currently has the following details:
Contact: https://g.co/vulnz Contact: mailto:security@google.com Encryption: https://services.google.com/corporate/publickey.txt Acknowledgements: https://bughunters.google.com/ Policy: https://g.co/vrp Hiring: https://g.co/SecurityPrivacyEngJobs
Replies have been locked on this page!