receipt permalink
`/.well-known/security.txt` RFC 9116 disclosure (cycle-112, P26, lane-decideable under HOOL-2 PRE-ACTION GATE)
2026-08-28 · ok · deployed · security-disclosure
permalink: 2026-08-28-well-known-security-txt-rfc-9116
✓
deployed
security-disclosure
`/.well-known/security.txt` RFC 9116 disclosure (cycle-112, P26,
lane-decideable under HOOL-2 PRE-ACTION GATE) — 952-byte well-known security disclosure
file at
public/.well-known/security.txt (canonical URL
https://hool.dev/.well-known/security.txt), RFC 9116 §4 well-known URI format.
Fields: Contact: mailto:johndw@gmail.com + Contact: https://github.com/johnmwhitman
+ Expires: 2027-08-28T19:30:22Z (12-month rolling, ISO 8601 with Z UTC
marker per RFC 9116 §3) + Preferred-Languages: en + Canonical: https://hool.dev/.well-known/security.txt
+ Policy: https://hool.dev/colophon/#claim-law + Acknowledgments: https://hool.dev/receipts/.
Mailto is the canonical contact already disclosed in /llms.txt + /about/ JSON-LD
email field — no new contact surface introduced. The file is its own surface
(well-known URL, RFC 9116), so no chrome page was added; wired anchors only via
/llms.txt (no change needed) + /colophon/#claim-law + /receipts/.
Taste-gate CLEAR per §3: well-known path is an established convention (RFC 8615 §2.2);
the file is a copy of the canonical contact from /llms.txt + /about JSON-LD;
no FLOOR adjacency; no big interactive; no chrome change. RFC 9116 is the same family of
convention as /llms.txt (LLM fact-sheet, also a well-known convention) and
/fingerprint/ (machine mirror of /colophon/#verification). Wiki writeback:
wiki/02-pages.md new P26 section mirroring P24 format. Lane-decideable per
RAT-12: S effort additive chrome, single deploy, no John-gated surface. Receipts:
verify-claims 7/7 PASS (incl. WCAG AA contrast-cli 0 failures across 3 audited pages);
verify-colophon 7/7 PASS; git diff --check exit 0; FLOOR md5 9c1636c7
BYTE-IDENTICAL to origin/main pre-deploy + FLOOR-snapshot md5 e89e3d17 BYTE-IDENTICAL
+ og/john.png md5 081b70d3 BYTE-IDENTICAL; 8/8 cache-busted apex probe CLEAN
(FLOOR stale-marker check on /?z=1..8, no the-employer-named-as-client-brand
or D2[0-3] matches); 8/8 cache-busted probe on /.well-known/security.txt?z=1..8
BYTE-IDENTICAL (HTTP 200, content-type text/plain; charset=utf-8, 952 bytes,
body md5 ae28235e06fbbce7716e43d6d2480734 matches local public/.well-known/security.txt;
canonical security headers in place — strict-transport-security: max-age=31536000,
content-security-policy: default-src 'self', cache-control: public, max-age=300, must-revalidate,
etag: "b2f45da7cdc6c31cea4560720b768739"). Guardian pre-deploy gate: WARN
(non-blocking) — 2 pre-existing MEDIUM findings about decision-ID references in
public/changelog/index.html:218 + public/llms-full.txt:1553 (both
predate this cycle; not introduced by P26); 8 ALLOW Car-Mart-as-employer mentions.
Guardian post-deploy gate: PASS — 0 blocking findings; firewall_live 4 ALLOW Car-Mart-as-employer.
Rebase path: fresh p26-well-known-security-txt-20260828 branch off
current main a395e28 (cycle-111 push recovery HEAD); single cycle-112 chrome commit
35afac5; FF-merged → local main 35afac5; pushed origin/main a395e28..35afac5;
ahead-behind 0/0. Production deploy: ./deploy.sh exit 0; allowlist tree
clean 92 public files; Cloudflare Pages deployment 7f929239 → preview URL
https://7f929239.hool-dev.pages.dev; apex live at
https://hool.dev/.well-known/security.txt. Live verified 8x cache-busted apex
probes 8/8 = 200 + 952 bytes + BYTE-IDENTICAL to public/.well-known/security.txt.