generated: '2026-09-02' method: searched probe: true source: https://github.com/foss42/apidash/blob/main/SECURITY.md note: >- 0-working/probe-security-programs.py reported vdp=none on 2026-09-02, and that is a true result for the paths it checks: neither host serves /.well-known/security.txt, and apidash.dev is an SPA whose edge returns the same HTML shell for /security and /responsible-disclosure. The program is real nonetheless — it lives in the repository rather than on the website, which is the normal shape for an open-source project. Recorded searched, with the probe result kept alongside it so the negative is not lost. policy: - https://github.com/foss42/apidash/blob/main/SECURITY.md intake: - kind: github-security-advisory url: https://github.com/foss42/apidash/security/advisories/new preferred: true note: SECURITY.md directs researchers to open a DRAFT security advisory for discussion and collaboration on the fix, and explicitly asks that vulnerabilities NOT be reported through public GitHub issues. - kind: email value: ankit[at]apidash.dev source: https://github.com/foss42/apidash/blob/main/doc/security/README.md note: Published de-obfuscated nowhere; recorded exactly as the provider writes it. scope: covers: API Dash application and the Dart/Flutter packages in the API Dash repository source: SECURITY.md ("management of vulnerabilities for API Dash project & the Dart/Flutter packages in the repository") requested_report_contents: - Type of issue (buffer overflow, poisoned dependency, cross-site scripting, etc.) - Full paths of source files related to the issue - Location of the affected source code (tag/branch/commit or direct URL) - Special configuration required to reproduce - Step-by-step reproduction instructions - Proof-of-concept or exploit code, if possible - Impact, including how an attacker might exploit it supporting_documentation: - {title: Threat Model, url: 'https://github.com/foss42/apidash/blob/main/doc/security/THREAT_MODEL.md'} - {title: Incident Response Plan, url: 'https://github.com/foss42/apidash/blob/main/doc/security/INCIDENT_RESPONSE_PLAN.md'} - {title: Security documentation index, url: 'https://github.com/foss42/apidash/blob/main/doc/security/README.md'} - {title: SBOM, url: 'https://github.com/foss42/apidash/blob/main/doc/security/sbom.json', note: 'A published software bill of materials — rare for a project this size and worth naming.'} bug_bounty: null bug_bounty_note: No HackerOne, Bugcrowd or Intigriti program was found. Disclosure is unpaid and coordinated through GitHub. response_sla: stated: false note: doc/security/README.md refers to "SLAs based on severity - see the IRP" but SECURITY.md itself states no numeric response time. evidence: - {source: 'https://github.com/foss42/apidash/blob/main/SECURITY.md', kind: security-policy, http_status: 429, note: 'GitHub rate-limited our crawler on this one URL; the raw.githubusercontent.com copy fetched 200 and its full text is quoted above. Not dead.'} - {source: 'https://raw.githubusercontent.com/foss42/apidash/main/SECURITY.md', kind: security-policy, http_status: 200} - {source: 'https://raw.githubusercontent.com/foss42/apidash/main/doc/security/README.md', kind: security-docs, http_status: 200} - {source: 'https://apidash.dev/.well-known/security.txt', kind: negative-probe, http_status: 200, verdict: 'soft-404 - SPA shell, 42967 bytes of HTML, identical to a random control path'} - {source: 'https://api.apidash.dev/.well-known/security.txt', kind: negative-probe, http_status: 404}