generated: '2026-09-03' method: searched source: https://artifactories.com/support (HTTP 200) + https://github.com/barangaroo/artifactories/security/policy (HTTP 200) note: >- probe-security-programs.py reported vdp=none because it looks for a security.txt Policy field or a named bug-bounty platform, and Artifactories has neither. It does publish a real, named private disclosure route on its support page, verified by probe. program_present: true program_type: private-vulnerability-reporting platform: github intake: url: https://github.com/barangaroo/artifactories/security/advisories/new http_status: 200 mechanism: GitHub private vulnerability reporting (enabled on the repository) policy: url: https://github.com/barangaroo/artifactories/security/policy http_status: 200 published_on: url: https://artifactories.com/support http_status: 200 effective_date: '2026-09-01' instruction: >- "Do not put secrets, exploit details, private keys, or personal data in a public issue. Report a vulnerability through GitHub private vulnerability reporting." security_txt: present: false probed: url: https://artifactories.com/.well-known/security.txt status: 404 gap: >- An RFC 9116 security.txt would make this route machine-discoverable. Today the disclosure path is only findable by reading the human support page or the GitHub repository. bug_bounty: present: false paid: false safe_harbor: published: false