generated: '2026-08-06' method: searched probe: true source: https://smartbear.com/security/ policy: - https://smartbear.com/security/ contact: - https://smartbear.com/security/ program: platform: HackerOne form: embedded detail: >- The SmartBear security page embeds a HackerOne "Submit Vulnerability Report" submission iframe (hackerone.com/425aeb5c-87dd-4bf5-8838-f8010fbaa396/embedded_submissions/new). There is no public HackerOne program page — hackerone.com/smartbear returns 404 — so the intake exists but the scope, rules of engagement and any bounty terms are not publicly published. public_program_page: false security_txt: false security_txt_note: >- No /.well-known/security.txt on swagger.io, generator.swagger.io or generator3.swagger.io (all 404). The disclosure channel is real but not machine-discoverable — a security.txt with Contact and Policy pointing at smartbear.com/security/ would close that gap. repository_policy: security_md: false detail: 'swagger-api/swagger-codegen publishes no SECURITY.md (404 at master and .github/).' evidence: - {source: 'https://smartbear.com/security/', http_status: 200, kind: disclosure-page, keywords: [hackerone, vulnerability report], fetched: '2026-08-06'} - {source: 'https://hackerone.com/smartbear', http_status: 404, kind: program-page-absent, fetched: '2026-08-06'} - {source: 'https://swagger.io/.well-known/security.txt', http_status: 404, kind: security.txt-absent, fetched: '2026-08-06'} - {source: 'https://raw.githubusercontent.com/swagger-api/swagger-codegen/master/SECURITY.md', http_status: 404, kind: repo-policy-absent, fetched: '2026-08-06'} control_check: note: >- smartbear.com returns a real 404 for unknown paths (control probe /zzz-control-nonexistent-abc/ -> 404, distinct title "Oops! This Page No Longer Exists"), so the 200 on /security/ is a genuine page, not a soft-404.