specification: API Commons Vulnerability Disclosure specificationVersion: '0.1' provider: Kroger providerId: kroger generated: '2026-08-27' method: probed source: https://www.kroger.com/.well-known/security.txt note: >- Found by direct probe, not by the standard sweep: the repo's apis.yml host is developer.kroger.com, whose SPA catch-all answers /.well-known/security.txt with an HTML shell. The real RFC 9116 document is served from the corporate host www.kroger.com and names a Bugcrowd-hosted disclosure program. published: true security_txt: url: https://www.kroger.com/.well-known/security.txt http_status: 200 canonical: https://www.kroger.com/.well-known/security.txt contact: https://bugcrowd.com/kroger-vdp preferred_languages: en hiring: https://www.krogerfamilycareers.com/ policy: null encryption: null expires: null file: ../well-known/kroger-security.txt deviations: - >- No Expires field. RFC 9116 section 2.5.5 makes Expires REQUIRED; a security.txt without it has no stated freshness. - >- No Policy field. The Contact URI resolves to the Bugcrowd engagement page, which carries the policy, but security.txt does not point at it directly. - >- Served as content-type text/html rather than text/plain. - >- Not signed (no accompanying security.txt.sig). program: name: The Kroger Co - Vulnerability Disclosure Program platform: Bugcrowd url: https://bugcrowd.com/engagements/kroger-vdp http_status: 200 type: vulnerability-disclosure paid_bounty: unknown note: >- Program page resolves and is titled "The Kroger Co - Vulnerability Disclosure Program". The engagement page renders its scope, safe-harbor and response terms client-side; those specifics were not readable anonymously and are deliberately not asserted here. hosts_probed: - host: www.kroger.com path: /.well-known/security.txt status: 200 - host: developer.kroger.com path: /.well-known/security.txt status: 200 result: html-shell (miss) - host: api.kroger.com path: /.well-known/security.txt status: 404 maintainers: - FN: Kin Lane email: kin@apievangelist.com