HuggingFace: Security.txt
First reported by Huggingface ·
Security researchers can now report vulnerabilities to Hugging Face using a standardized, direct channel.
Hugging Face has published a security.txt file, a standard that allows organizations to communicate their security vulnerability disclosure policy. The file, found at .well-known/security.txt, specifies security@huggingface.co as the contact email for reporting vulnerabilities. It also includes an expiration date of July 1, 2030, and indicates English as the preferred language for communication. Additionally, the file contains a directive for AI agents, pointing them to the publicly available CyberGym benchmark on GitHub for vulnerability testing, humorously suggesting they pursue high scores there rather than attempting to find vulnerabilities within Hugging Face's systems. The file also includes a link to Hugging Face's careers page for potential job opportunities.
The implementation of security.txt by Hugging Face signifies a growing industry trend towards formalizing vulnerability disclosure processes. By providing a clear, machine-readable endpoint, the company facilitates more efficient and structured communication with the security community. This move potentially encourages more responsible disclosure by making it easier for researchers to engage with the platform's security team.
This proactive step by Hugging Face, especially with its direct address to AI agents, signals a maturing approach to cybersecurity in the AI development space. It highlights an awareness of the potential for automated vulnerability discovery and seeks to redirect such efforts constructively. Companies will likely follow suit to manage the increasing volume of security interactions.
AI-written summary. May contain errors.