Feature

Vulnerability Disclosure & Bug Bounty

A published path for reporting security issues.

5 providers 6 APIs 3 declared variants

A security.txt, VDP, or bug-bounty program gives researchers a defined way to report vulnerabilities. Signals a provider that expects and handles security findings.

5 API providers on the APIs.io network offer vulnerability disclosure & bug bounty. The highest-rated are BeyondTrust, Packagist, US Cyber Command, Cybereason, Axonius.

Providers

Ranked by API Evangelist rating — Exemplar and Strong are expanded by default.

Developing 2 Usable, with meaningful gaps to close
Thin 3 Limited public surface area

What Providers Actually Declared

This feature is a canonical term. These are the free-text strings providers wrote in their own apis.yml that map onto it.

Joint Cybersecurity AdvisoriesSecurity advisories API aggregating FriendsOfPHP, GitHub Advisory Database, and PSA sourcesVulnerability Management

Scroll for all 3