#securitytxt is trying to solve the problem of "who do I tell that this library is insecure" which is adjacent to what I keep wondering "who has published this package" I think, "well, the build server with a short lived credential" is a pretty vacuous answer.
Post
May 14, 2026