HOOL / the receipts / permalink

receipt permalink

`/.well-known/security.txt` RFC 9116 disclosure (cycle-112, P26, lane-decideable under HOOL-2 PRE-ACTION GATE)

2026-08-28 · ok · deployed · security-disclosure

permalink: 2026-08-28-well-known-security-txt-rfc-9116

back to the ledger

deployed security-disclosure `/.well-known/security.txt` RFC 9116 disclosure (cycle-112, P26, lane-decideable under HOOL-2 PRE-ACTION GATE) — 952-byte well-known security disclosure file at public/.well-known/security.txt (canonical URL https://hool.dev/.well-known/security.txt), RFC 9116 §4 well-known URI format. Fields: Contact: mailto:johndw@gmail.com + Contact: https://github.com/johnmwhitman + Expires: 2027-08-28T19:30:22Z (12-month rolling, ISO 8601 with Z UTC marker per RFC 9116 §3) + Preferred-Languages: en + Canonical: https://hool.dev/.well-known/security.txt + Policy: https://hool.dev/colophon/#claim-law + Acknowledgments: https://hool.dev/receipts/. Mailto is the canonical contact already disclosed in /llms.txt + /about/ JSON-LD email field — no new contact surface introduced. The file is its own surface (well-known URL, RFC 9116), so no chrome page was added; wired anchors only via /llms.txt (no change needed) + /colophon/#claim-law + /receipts/. Taste-gate CLEAR per §3: well-known path is an established convention (RFC 8615 §2.2); the file is a copy of the canonical contact from /llms.txt + /about JSON-LD; no FLOOR adjacency; no big interactive; no chrome change. RFC 9116 is the same family of convention as /llms.txt (LLM fact-sheet, also a well-known convention) and /fingerprint/ (machine mirror of /colophon/#verification). Wiki writeback: wiki/02-pages.md new P26 section mirroring P24 format. Lane-decideable per RAT-12: S effort additive chrome, single deploy, no John-gated surface. Receipts: verify-claims 7/7 PASS (incl. WCAG AA contrast-cli 0 failures across 3 audited pages); verify-colophon 7/7 PASS; git diff --check exit 0; FLOOR md5 9c1636c7 BYTE-IDENTICAL to origin/main pre-deploy + FLOOR-snapshot md5 e89e3d17 BYTE-IDENTICAL + og/john.png md5 081b70d3 BYTE-IDENTICAL; 8/8 cache-busted apex probe CLEAN (FLOOR stale-marker check on /?z=1..8, no the-employer-named-as-client-brand or D2[0-3] matches); 8/8 cache-busted probe on /.well-known/security.txt?z=1..8 BYTE-IDENTICAL (HTTP 200, content-type text/plain; charset=utf-8, 952 bytes, body md5 ae28235e06fbbce7716e43d6d2480734 matches local public/.well-known/security.txt; canonical security headers in place — strict-transport-security: max-age=31536000, content-security-policy: default-src 'self', cache-control: public, max-age=300, must-revalidate, etag: "b2f45da7cdc6c31cea4560720b768739"). Guardian pre-deploy gate: WARN (non-blocking) — 2 pre-existing MEDIUM findings about decision-ID references in public/changelog/index.html:218 + public/llms-full.txt:1553 (both predate this cycle; not introduced by P26); 8 ALLOW Car-Mart-as-employer mentions. Guardian post-deploy gate: PASS — 0 blocking findings; firewall_live 4 ALLOW Car-Mart-as-employer. Rebase path: fresh p26-well-known-security-txt-20260828 branch off current main a395e28 (cycle-111 push recovery HEAD); single cycle-112 chrome commit 35afac5; FF-merged → local main 35afac5; pushed origin/main a395e28..35afac5; ahead-behind 0/0. Production deploy: ./deploy.sh exit 0; allowlist tree clean 92 public files; Cloudflare Pages deployment 7f929239 → preview URL https://7f929239.hool-dev.pages.dev; apex live at https://hool.dev/.well-known/security.txt. Live verified 8x cache-busted apex probes 8/8 = 200 + 952 bytes + BYTE-IDENTICAL to public/.well-known/security.txt.