specification: API Commons Vulnerability Disclosure specificationVersion: '0.1' provider: Advance Auto Parts providerId: advance-auto-parts generated: '2026-08-30' method: searched source: https://hackerone.com/advanceauto program: present: true platform: HackerOne handle: advanceauto url: https://hackerone.com/advanceauto type: vulnerability-disclosure-program verified_owner: true owner_evidence: >- The HackerOne team object served anonymously at https://hackerone.com/advanceauto?type=team (HTTP 200, application/json) names the team "Advance Auto Parts" with profile.website "http://AdvanceAutoParts.com" and twitter_handle "advanceauto" — the program is confirmed to belong to this company rather than to a similarly-named third party. bounty: unknown policy_text: >- Not captured. The HackerOne program page is client-rendered and returned no policy text to an unauthenticated fetch; only the team metadata object is machine-readable. x-evidence: - url: https://hackerone.com/advanceauto http_status: 200 fetched: '2026-08-30' - url: https://hackerone.com/advanceauto?type=team http_status: 200 content_type: application/json fetched: '2026-08-30' - url: https://www.advanceautoparts.com/.well-known/security.txt http_status: 200 result: zero-byte body (Akamai bot mitigation) — no security.txt is served fetched: '2026-08-30' - url: https://supplier.advanceautoparts.com/.well-known/security.txt http_status: 404 fetched: '2026-08-30' note: >- Advance Auto Parts runs a named vulnerability disclosure program on HackerOne, but does NOT advertise it from its own infrastructure: no /.well-known/security.txt is served on any of the five hosts probed (www, shop, api, supplier, my.advancepro). A researcher who follows RFC 9116 finds nothing; the program is only discoverable through HackerOne. That is the concrete, cheap fix here.