Dick's Sporting Goods · Vulnerability Disclosure
Dicks Sporting Goods Vulnerability Disclosure
Vulnerability disclosure
Dick’s Sporting Goods runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served.
RetailSporting GoodsFortune 500E-CommerceOmnichannel CommerceConsumer Goods
Program: Hackerone
security.txt present
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-09-06'
method: searched
probe: true
source: https://bugcrowd.com/engagements/dickssportinggoods
note: >-
DICK'S Sporting Goods runs a named, first-party Vulnerability Disclosure Program on
Bugcrowd. The program page returns HTTP 200 and identifies the company in its own
OpenGraph metadata — og:title "DICK'S Sporting Goods | Bugcrowd", og:description
"Learn more about DICK'S Sporting Goods's Vulnerability Disclosure engagement powered
by Bugcrowd, the leader in crowdsourced security solutions" — and carries the company
logo at logos.bugcrowdusercontent.com. That is a disclosure surface the company
operates, and it is the ONLY machine-findable security-program artifact this company
publishes: /.well-known/security.txt is not served on any host (see
well-known/dicks-sporting-goods-well-known.yml — the storefront answers 200 with an
Angular app shell for every path, including a control path that cannot exist).
program_type: vulnerability-disclosure
paid_bounty: false
policy:
- https://bugcrowd.com/engagements/dickssportinggoods
contact: []
security_txt: false
evidence:
- source: https://bugcrowd.com/engagements/dickssportinggoods
kind: bug-bounty-platform
platform: bugcrowd
http_status: 200
fetched: '2026-09-06'
signals:
- 'og:title: DICK''S Sporting Goods | Bugcrowd'
- 'og:description: Learn more about DICK''S Sporting Goods''s Vulnerability Disclosure engagement powered by Bugcrowd'
- 'title: Vulnerability Disclosure: DICK''S Sporting Goods - Bugcrowd'
- source: https://bugcrowd.com/dickssportinggoods
kind: bug-bounty-platform
platform: bugcrowd
http_status: 200
fetched: '2026-09-06'
note: Alias of the engagement URL above; serves the identical page.
- source: https://hackerone.com/dicks
kind: bug-bounty-platform
platform: hackerone
http_status: 200
fetched: '2026-09-06'
note: >-
A HackerOne page exists at this handle and is indexed as "Dick's Sporting Goods |
Vulnerability Disclosure Policy", but the served body is a 2.3KB JavaScript app
shell with no company-identifying content, so it is recorded as a lead rather than
as confirmed first-party evidence. Bugcrowd is the surface that self-identifies.
- source: https://www.dickssportinggoods.com/.well-known/security.txt
kind: security.txt
http_status: 200
fetched: '2026-09-06'
result: miss
note: >-
Soft 404 — 2691 bytes of Angular app shell, not RFC 9116 text. The same shell is
returned for a negative-control path, so the 200 is meaningless.
gaps:
- >-
No /.well-known/security.txt on any host, so the disclosure program is undiscoverable
by the RFC 9116 mechanism a scanner or an agent would use. Bugcrowd hosts the policy;
the company's own domain does not point at it.
- >-
No security contact email published on a company-controlled surface.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/dicks-sporting-goods-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.