Restructuring GitHub's bug bounty program
github.blog
Restructuring GitHub's bug bounty program
1–10 of 38 posts
Re: Restructuring GitHub's bug bounty program
#2Re: Restructuring GitHub's bug bounty program
#3Re: Restructuring GitHub's bug bounty program
#4So if the "wrong" person finds a critical vulnerability in GitHub, the payout is capped at $10,000. Might reduce the likelihood of it being submitted to the bug bounty program.
Tragedy of the commons that someone who hasn’t passed the filter yet might have their payout limited.
Vouch - https://news.ycombinator.com/item?id=46930961 - February 2026 (486 comments)
Re: Restructuring GitHub's bug bounty program
#5So if the "wrong" person finds a critical vulnerability in GitHub, the payout is capped at $10,000. Might reduce the likelihood of it being submitted to the bug bounty program.
Re: Restructuring GitHub's bug bounty program
#6So if the "wrong" person finds a critical vulnerability in GitHub, the payout is capped at $10,000. Might reduce the likelihood of it being submitted to the bug bounty program.
It might, but as someone who has to review public vulnerability reports for a much less popular website, I completely understand why they’re building a vouch program to dissuade slop reports. One would presume their internal team is using frontier models for red team agent scanning against potential attack surface, and so this is a potential risk they’re willing to take. Tragedy of the commons that someone who hasn’t…
So, researchers first need to collect some positive rep. But the rep points are global, so once you have fixed a few bugs for Google, you've gotten enough +rep that you can also receive stuff at GitHub.
Oh, and ID check when signing up at H1.
Long term all beg bounty submitters would be banned for pretty much all of tech.
Re: Restructuring GitHub's bug bounty program
#7Re: Restructuring GitHub's bug bounty program
#8Re: Restructuring GitHub's bug bounty program
#9So if the "wrong" person finds a critical vulnerability in GitHub, the payout is capped at $10,000. Might reduce the likelihood of it being submitted to the bug bounty program.
It might, but as someone who has to review public vulnerability reports for a much less popular website, I completely understand why they’re building a vouch program to dissuade slop reports. One would presume their internal team is using frontier models for red team agent scanning against potential attack surface, and so this is a potential risk they’re willing to take. Tragedy of the commons that someone who hasn’t…