Also, to be clear, I genuinely appreciate the constructive criticism. It is helpful for all of us (I could be wrong, even if operating from what I believe to be best available knowledge). We all learn together. My apologies if my comment came across otherwise. I want my ideas to be torn apart, in the same way one would defend a thesis amongst peers. Winning arguments is not important to me; my goal is to explore the problem space and hopefully be implementing what is the best solution to a problem. If I am wrong or can do better, I want to know.
You’ll get the same amount of spam and irrelevant random bug bounty demanders. There’s no substitute to having someone look at the messages and find that needle in the haystack.
Though there are some signal to noise ratio tricks: https://xkcd.com/1181/
I can also control security.txt through Cloudflare as an option, and have less control of website content.
https://developers.cloudflare.com/security-center/infrastruc...
But those who notice a problem do have some point of aggravation past which they'll just go "I can't be bothered; fuck 'em". You really do want to make it as easy as possible for them to report. (And alsp make it seem as safe as possible; having a reputation for suing reporters is also terrible.)
Now, in practice, I don't thing security.txt is a particularly useful way of doing this, but it is pretty easy to add.
After 3 years: ZERO spam