generated: '2026-08-27' method: probed source: probed 2026-08-27 (probe-security-programs.py sparkyfitness -> vdp=none) published: false security_txt: present: false probed: - url: https://codewithcj.github.io/.well-known/security.txt status: 404 - url: https://codewithcj.github.io/SparkyFitness/.well-known/security.txt status: 404 bug_bounty: present: false programs_probed: [HackerOne, Bugcrowd, Intigriti] security_policy_file: present: false note: >- No SECURITY.md at the repository root and none under .github/ — that directory holds CODEOWNERS, FUNDING.yml, ISSUE_TEMPLATE, release config and workflows, but no security policy. GitHub therefore shows no "Report a vulnerability" route on this repository. finding: >- There is no coordinated vulnerability disclosure route. A researcher who finds a flaw in a project with 5,653 stars, 335 forks and ~1.2M pulls of each Docker image has nowhere to send it privately: the only public channels are the issue tracker, Discussions and Discord, all of which disclose the report to everyone the moment it is filed. This is the cheapest high-value fix available to the project — a SECURITY.md naming an email address would close it. NO `Security` pointer is emitted, because there is no disclosure surface to point at.