Description
The security contact should be [email protected]. Bad Bundle already publishes that address in badbundle.com's own /.well-known/security.txt (bad-bundle-web).
Trackslash currently tells reporters to use [email protected], but trackslash.com has no MX records (checked 2026-09-28), so reports sent there bounce.
Change
SECURITY.md(line 5): the reporting address.legal/SECURITY.md(line 10): the policy served at/security.internal/server/ui_site_metadata.go:securityContactAddress, which is theContact:line in/.well-known/security.txt.internal/server/preview_terms_integration_test.go: the/securitycase expects the old address.ui_site_metadata_test.goreads the constant, so it follows automatically.- CSS: run
npm run assetsafter the Go change and commitapp.cssif it changed, since Tailwind scans Go files.
Before merging
Check that badbundle.com's Cloudflare Email Routing delivers security@ (a specific rule or a catch-all), for example by sending it a test message.
Same problem, decision needed
Two more contact addresses on trackslash.com also bounce:
[email protected], inlegal/PRIVACY.mdtwice. It's the contact for privacy and data-protection requests.[email protected], inTRADEMARKS.mdandlegal/TERMS.md.
The options:
- Move them to badbundle.com addresses too. Other Bad Bundle apps use
[email protected]and[email protected]. - Turn on Email Routing for trackslash.com, so the existing addresses work.
Recommended: move them in the same PR. Then trackslash.com needs no incoming mail at all, and TRACK-96 only has to set up sending.
Done when
- Every security contact in the repo, the
/securitypage andsecurity.txtsays[email protected]. privacy@andlegal@are handled as decided above.- Tests and
npm run assets:checkpass. - A test email to each published address arrives.
Linked issues
1Sub-issues
0GitHub
0No branches or pull requests linked.
Comments
0No comments.