Dick's Sporting Goods · Vulnerability Disclosure

Dicks Sporting Goods Vulnerability Disclosure

Vulnerability disclosure

Dick’s Sporting Goods runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served.

RetailSporting GoodsFortune 500E-CommerceOmnichannel CommerceConsumer Goods
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Source

Vulnerability Disclosure

dicks-sporting-goods-vulnerability-disclosure.yml Raw ↑
generated: '2026-09-06'
method: searched
probe: true
source: https://bugcrowd.com/engagements/dickssportinggoods
note: >-
  DICK'S Sporting Goods runs a named, first-party Vulnerability Disclosure Program on
  Bugcrowd. The program page returns HTTP 200 and identifies the company in its own
  OpenGraph metadata — og:title "DICK'S Sporting Goods | Bugcrowd", og:description
  "Learn more about DICK'S Sporting Goods's Vulnerability Disclosure engagement powered
  by Bugcrowd, the leader in crowdsourced security solutions" — and carries the company
  logo at logos.bugcrowdusercontent.com. That is a disclosure surface the company
  operates, and it is the ONLY machine-findable security-program artifact this company
  publishes: /.well-known/security.txt is not served on any host (see
  well-known/dicks-sporting-goods-well-known.yml — the storefront answers 200 with an
  Angular app shell for every path, including a control path that cannot exist).
program_type: vulnerability-disclosure
paid_bounty: false
policy:
  - https://bugcrowd.com/engagements/dickssportinggoods
contact: []
security_txt: false
evidence:
  - source: https://bugcrowd.com/engagements/dickssportinggoods
    kind: bug-bounty-platform
    platform: bugcrowd
    http_status: 200
    fetched: '2026-09-06'
    signals:
      - 'og:title: DICK''S Sporting Goods | Bugcrowd'
      - 'og:description: Learn more about DICK''S Sporting Goods''s Vulnerability Disclosure engagement powered by Bugcrowd'
      - 'title: Vulnerability Disclosure: DICK''S Sporting Goods - Bugcrowd'
  - source: https://bugcrowd.com/dickssportinggoods
    kind: bug-bounty-platform
    platform: bugcrowd
    http_status: 200
    fetched: '2026-09-06'
    note: Alias of the engagement URL above; serves the identical page.
  - source: https://hackerone.com/dicks
    kind: bug-bounty-platform
    platform: hackerone
    http_status: 200
    fetched: '2026-09-06'
    note: >-
      A HackerOne page exists at this handle and is indexed as "Dick's Sporting Goods |
      Vulnerability Disclosure Policy", but the served body is a 2.3KB JavaScript app
      shell with no company-identifying content, so it is recorded as a lead rather than
      as confirmed first-party evidence. Bugcrowd is the surface that self-identifies.
  - source: https://www.dickssportinggoods.com/.well-known/security.txt
    kind: security.txt
    http_status: 200
    fetched: '2026-09-06'
    result: miss
    note: >-
      Soft 404 — 2691 bytes of Angular app shell, not RFC 9116 text. The same shell is
      returned for a negative-control path, so the 200 is meaningless.
gaps:
  - >-
    No /.well-known/security.txt on any host, so the disclosure program is undiscoverable
    by the RFC 9116 mechanism a scanner or an agent would use. Bugcrowd hosts the policy;
    the company's own domain does not point at it.
  - >-
    No security contact email published on a company-controlled surface.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/dicks-sporting-goods-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.