DICK'S Sporting Goods recognizes the importance of security, privacy and community, and values the input of hackers acting in good-faith to help us maintain a high standard for our users. This includes encouraging responsible vulnerability research and the disclosure of security vulnerabilities.
Our vulnerability disclosure policy describes our expectations throughout this process, the channels we’ve created for hackers to communicate with us, and what you can expect from us in return.
Thank you for your interest in making the Internet safer!
For the initial prioritization/rating of findings, this program will use the Bugcrowd Vulnerability Rating Taxonomy. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.
This program follows Bugcrowd’s standard disclosure terms.
For any testing issues (such as broken credentials, inaccessible application, or Bugcrowd Ninja email problems), please email firstname.lastname@example.org. We will address your issue as soon as possible.