SparkyFitness · Vulnerability Disclosure

Sparkyfitness Vulnerability Disclosure

Vulnerability disclosure

SparkyFitness runs a coordinated vulnerability disclosure program on Hackerone.

CompanyHealthFitnessNutritionSelf-HostedOpen-SourceWearablesMCPAI AssistantQuantified Self
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-27'
method: probed
source: probed 2026-08-27 (probe-security-programs.py sparkyfitness -> vdp=none)
published: false
security_txt:
  present: false
  probed:
    - url: https://codewithcj.github.io/.well-known/security.txt
      status: 404
    - url: https://codewithcj.github.io/SparkyFitness/.well-known/security.txt
      status: 404
bug_bounty:
  present: false
  programs_probed: [HackerOne, Bugcrowd, Intigriti]
security_policy_file:
  present: false
  note: >-
    No SECURITY.md at the repository root and none under .github/ — that
    directory holds CODEOWNERS, FUNDING.yml, ISSUE_TEMPLATE, release config and
    workflows, but no security policy. GitHub therefore shows no "Report a
    vulnerability" route on this repository.
finding: >-
  There is no coordinated vulnerability disclosure route. A researcher who finds
  a flaw in a project with 5,653 stars, 335 forks and ~1.2M pulls of each Docker
  image has nowhere to send it privately: the only public channels are the issue
  tracker, Discussions and Discord, all of which disclose the report to everyone
  the moment it is filed. This is the cheapest high-value fix available to the
  project — a SECURITY.md naming an email address would close it. NO `Security`
  pointer is emitted, because there is no disclosure surface to point at.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/sparkyfitness-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.