A vulnerability disclosure policy (VDP), also referred to as a responsible disclosure policy, describes how an organization will handle reports of vulnerabilities submitted by ethical hackers. A VDP must thus be easily identifiable via a simple way, a security.txt notice.
Contact: mailto:VulnerabilityReporting@McKesson.com Contact: mailto:mckesson@submit.bugcrowd.com Contact: https://bugcrowd.com/engagements/mckesson-vdp-pro Expires: 2026-04-21T04:00:00.000Z Encryption: https://mckcvd.blob.core.windows.net/cvd/GPGKey.txt Preferred-Languages: en Policy: https://www.mckesson.com/cybersecurity/coordinated-vulnerability-disclosure/ Hiring: https://careers.mckesson.com/en/search-jobs/security/
This policy crawled by Onyphe on the 2025-08-03 is sorted as securitytxt.
FireBounty © 2015-2025