Release engineering, simplified https://goreleaser.com
  • Go 92.2%
  • Ruby 3%
  • Nix 1.7%
  • HTML 1.4%
  • YAML 1%
  • Other 0.7%
Find a file
Kobi Hikri ae4debbe43
docs: add /.well-known/security.txt (RFC 9116) (#6710)
Hi, and thank you for GoReleaser.

This adds a machine-readable `/.well-known/security.txt` (RFC 9116) to
the site's `www/static/` dir, so it serves at
`https://goreleaser.com/.well-known/security.txt` (currently 404). It
points automated tooling at the disclosure channel your `SECURITY.md`
already documents (GitHub Security Advisories):

```
Contact: https://github.com/goreleaser/goreleaser/security/advisories/new
Policy: https://github.com/goreleaser/goreleaser/blob/main/SECURITY.md
Preferred-Languages: en
Canonical: https://goreleaser.com/.well-known/security.txt
Expires: 2027-01-01T00:00:00.000Z
```

I verified the `www/static/` passthrough serves at the site root (e.g.
`goreleaser.com/favicon.ico` and `/card.png` both return 200), so this
file will be served at the well-known path. RFC 9116 recommends
refreshing `Expires` at least annually — feel free to adjust.

Per your AI usage guidelines: AI assistance was used to identify this
and draft the file (the commit carries an `Assisted-by` marker). I fully
reviewed the change and verified the live 404, the serving passthrough,
and the SECURITY.md channel myself.
2026-07-15 17:53:58 -03:00
.copilot/skills/authoring-docs docs: doc authoring skill 2026-06-18 10:44:30 -03:00
.github ci(deps): bump the actions group with 8 updates (#6703) 2026-07-10 10:57:59 -03:00
cmd feat(builders): add node sea support (#6579) 2026-05-03 00:05:20 -03:00
internal fix: migrate from deprecated s3/manager to s3/transfermanager (#6706) 2026-07-13 22:16:39 -03:00
pkg feat(scm): allow a custom token on the release repository (#6689) 2026-07-03 10:07:19 -03:00
scripts ci: improve get-releases script 2026-06-20 20:43:08 -03:00
testdata/TestVersion
www docs: add /.well-known/security.txt (RFC 9116) (#6710) 2026-07-15 17:53:58 -03:00
.editorconfig
.gitattributes feat(builders): add node sea support (#6579) 2026-05-03 00:05:20 -03:00
.gitignore
.golangci.yaml
.goreleaser.yaml ci: verify 2026-07-04 11:24:31 -03:00
.grype.yaml
.mailmap
.svu.yml
art.txt
CONTRIBUTING.md
Dockerfile chore(deps): bump the docker group across 1 directory with 2 updates (#6702) 2026-07-10 10:58:33 -03:00
EULA.md
go.mod fix: migrate from deprecated s3/manager to s3/transfermanager (#6706) 2026-07-13 22:16:39 -03:00
go.sum chore(deps): bump the gomod group with 6 updates (#6701) 2026-07-10 10:56:18 -03:00
INCIDENT_RESPONSE.md
LICENSE.md
main.go
main_test.go
README.md chore: auto-update generated files (#6675) 2026-06-26 13:13:37 -03:00
SECURITY.md
Taskfile.yml ci: improve ci times (#6677) 2026-06-27 14:01:17 -03:00
THREAT_MODEL.md
USERS.md docs(users): update charm domain (#6699) 2026-07-08 17:43:46 -03:00

GoReleaser Logo

GoReleaser

Release engineering, simplified.

Go Rust Zig TypeScript Python


We handle the complexities of releasing so you can focus in building what really matters: your software.


Get GoReleaser

Documentation

Documentation is hosted live at https://goreleaser.com

Community

You have questions, need support and or just want to talk about GoReleaser?

Here are ways to get in touch with the GoReleaser community:

Follow on 𝕏 Follow Telegram Channel GitHub Discussions

You can find the links above and all others here.

Code of Conduct

This project adheres to the Contributor Covenant code of conduct. By participating, you are expected to uphold this code. We appreciate your contribution. Please refer to our contributing guidelines for further information.

Badges

Release Software License Build status Codecov branch Artifact Hub Go Doc Powered By: GoReleaser Backers on Open Collective Sponsors on Open Collective Conventional Commits CII Best Practices GoReportCard

Contributing

This project exists thanks to all the people who contribute. Contribution guide.

Sponsoring

Does you or your company use GoReleaser?

You can help keep the project bug-free and feature rich by sponsoring the project and its maintainers.

You can sponsor GoReleaser via:

A big thank you to all current, past, and future sponsors!


Our Sponsors

Diamond
SerpApi

Gold
GitHub SecureOSS Fund nitric

Silver
Depot N-iX Ltd

Bronze
conet cloud Encore Comet Gitea

And many more!

See the full list here.