惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

阮一峰的网络日志
阮一峰的网络日志
GbyAI
GbyAI
WordPress大学
WordPress大学
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
小众软件
小众软件
博客园 - 叶小钗
有赞技术团队
有赞技术团队
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
量子位
S
SegmentFault 最新的问题
博客园 - 三生石上(FineUI控件)
J
Java Code Geeks
S
Security Affairs
Cisco Talos Blog
Cisco Talos Blog
Jina AI
Jina AI
L
LINUX DO - 热门话题
Microsoft Security Blog
Microsoft Security Blog
aimingoo的专栏
aimingoo的专栏
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
S
Secure Thoughts
Stack Overflow Blog
Stack Overflow Blog
罗磊的独立博客
H
Hacker News: Front Page
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
T
Tenable Blog
The Last Watchdog
The Last Watchdog
P
Proofpoint News Feed
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
IT之家
IT之家
A
About on SuperTechFans
AWS News Blog
AWS News Blog
MyScale Blog
MyScale Blog
The Register - Security
The Register - Security
T
Threatpost
Last Week in AI
Last Week in AI
The Hacker News
The Hacker News
V
Visual Studio Blog
C
Cyber Attacks, Cyber Crime and Cyber Security
S
Security @ Cisco Blogs
Project Zero
Project Zero
N
News | PayPal Newsroom
MongoDB | Blog
MongoDB | Blog
爱范儿
爱范儿
K
Kaspersky official blog
雷峰网
雷峰网
W
WeLiveSecurity
博客园 - 聂微东
D
DataBreaches.Net
博客园 - 司徒正美
V2EX - 技术
V2EX - 技术

The GitHub Blog

How to build interactive experiences with canvases $100 million for open source: A milestone built by the community The cost of saying yes has changed GitHub for Beginners: Your roadmap to mastering the GitHub essentials Better tools made Copilot code review worse. Here's how we actually improved it. How GitHub gave every repository a durable owner Automating cross-repo documentation with GitHub Agentic Workflows GitHub availability report: June 2026 How GitHub Copilot enables zero DNS configuration for GitHub Pages Q1 2026 Innovation Graph update: Open source collaboration is accelerating worldwide How GitHub used secret scanning to reach inbox zero 6 security settings every GitHub maintainer should enable this week How GitHub maintains compliance for open source dependencies Highlights from Git 2.55 Inside the Advisory Database and what happens when vulnerability volume breaks records GitHub and UNDP team up to advance development priorities in Ghana with open source Transitioning as a Hubber Evaluating performance and efficiency of the GitHub Copilot agentic harness across models and tasks I automated my job (and it made me a better leader) GitHub joins coalition advocating for fixes to California AI Transparency Act to protect open source From pledge to practice: Building a more inclusive open source ecosystem How we built an internal data analytics agent How pull request limits are cutting down the noise Getting more from each token: How Copilot improves context handling and model routing What are git worktrees, and why should I use them? GitHub Copilot CLI for Beginners: Overview of common slash commands Accelerating researchers and developers building multilingual AI with a new open dataset How we made GitHub Copilot CLI more selective about delegation GitHub availability report: May 2026 Making secret scanning more trustworthy: Reducing false positives at scale Give GitHub Copilot CLI real code intelligence with language servers From one-off prompts to workflows: How to use custom agents in GitHub Copilot CLI GitHub for Beginners: Answers to some common questions GitHub Universe is back: All together now, in the agentic era GitHub Copilot app: The agent-native desktop experience Still a developer. Just outside. Our latest GitHub Shop collection is here. GitHub for Beginners: Getting started with Git and GitHub in VS Code GitHub recognized as a Leader in the Gartner® Magic Quadrant™ for Enterprise AI Coding Agents for the third year in a row Beyond the engine: 10 open source projects shaping how games actually get made Building GitHub’s next chapter in accessibility Investigation update: GitHub Enterprise Server signing key rotation Take your local GitHub sessions anywhere Building a general-purpose accessibility agent—and what we learned in the process Raising the bar: Quality, shared responsibility, and the future of GitHub’s bug bounty program GitHub availability report: April 2026 From latency to instant: Modernizing GitHub Issues navigation performance Dungeons & Desktops: 10 roguelikes that never die (because their communities won’t let them) GitHub Copilot individual plans: Introducing flex allotments in Pro and Pro+, and a new Max plan Dungeons & Desktops: Building a procedurally generated roguelike with GitHub Copilot CLI GitHub for Beginners: Getting started with OSS contributions Why age assurance laws matter for developers How researchers are using GitHub Innovation Graph data to reveal the “digital complexity” of nations Improving token efficiency in GitHub Agentic Workflows Agent pull requests are everywhere. Here’s how to review them. Validating agentic behavior when “correct” isn’t deterministic Welcome to Maintainer Month: Celebrating the people behind the code Register now for OpenClaw: After Hours @ GitHub GitHub Copilot CLI for Beginners: Interactive v. non-interactive mode GitHub for Beginners: Getting started with Markdown Securing the git push pipeline: Responding to a critical remote code execution vulnerability Highlights from Git 2.54 Building an emoji list generator with the GitHub Copilot CLI Bringing more transparency to GitHub’s status page How GitHub uses eBPF to improve deployment safety Build a personal organization command center with GitHub Copilot CLI Developer policy update: Intermediary liability, copyright, and transparency Hack the AI agent: Build agentic AI security skills with the GitHub Secure Code Game How exposed is your code? Find out in minutes—for free GitHub for Beginners: Getting started with GitHub Pages GitHub Copilot CLI for Beginners: Getting started with GitHub Copilot CLI GitHub availability report: March 2026 GitHub Universe is back: We want you to take the stage GitHub Copilot CLI combines model families for a second opinion The uphill climb of making diff lines performant Securing the open source supply chain across GitHub Run multiple agents at once with /fleet in Copilot CLI Agent-driven development in Copilot Applied Science GitHub for Beginners: Getting started with GitHub security What’s coming to our GitHub Actions 2026 security roadmap
Next chapter: Restructuring GitHub's bug bounty program
Catherine Cassell · 2026-07-23 · via The GitHub Blog

The security research community makes GitHub safer for everyone. That’s the simple idea behind our bug bounty program.

For more than a decade, researchers from around the world have helped us find and fix vulnerabilities before they could be exploited, and we’ve worked hard to be a program worth their time.

Today, we’re sharing some meaningful changes to how the program works. These decisions comes after months of reflecting on our program, analyzing what’s happening across the industry, and thinking about researcher experience.

What’s changed and why

The program is facing an increasing queue. We have already made adjustments to accommodate the rise in new researchers and the acceleration in efforts of researchers we’ve been working with. We shared these changes in a recent blog post.

These changes are about two things: reducing the noise so we can focus on the signal, and building a program that serious researchers find rewarding to participate in.

Introducing a permanent VIP program

We’re formalizing a permanent private/invite-only VIP program for qualified researchers who consistently deliver high-quality, high-impact work. VIP researchers get higher payouts, faster response times, and a closer working relationship with our security engineering team. The goal is to create a space where the researchers who invest deeply in understanding GitHub can work with us directly and get an experience that reflects the effort they put in.

VIP program bounty table:

Severity Payout 
Low $1,000 
Medium $7,500 
High $20,000 
Critical $30,000+ 

How to qualify: We’ll publish clear criteria on our public HackerOne page. The path in is built around demonstrated, consistent quality. To qualify, you must accomplish at least one of the following:

  • One critical finding
  • Two high findings
  • Four medium findings
  • Seven low findings

The core shift here is in what we’re incentivizing: you don’t earn more by submitting more. You earn more by submitting better.

A restructured public bounty table

To commit ourselves to the changes in our prioritization above, we also must make changes that enable it. We are adjusting our public program rates to accommodate this shift in focus towards quality of relationships and findings over quantity of reports. We are also updating to static payouts—a single, clear number per severity level, rather than a wide range. Ranges sound flexible, but in practice they create uncertainty for researchers and overhead for our team. Static payouts set clear expectations on both sides, and we retain the ability to award discretionary bonuses for work that goes above and beyond.

Our new public program bounty table:

Severity Payout 
Low $250 
Medium $2,000 
High $5,000 
Critical $10,000 

This adjustment will enable us to provide more tailored attention and higher rewards to our VIP program, while still enabling our public program to be a place to explore and serve as a feeder into the VIP program.

Raising the signal requirement

To reduce the volume of low-effort and AI-generated reports, we’re implementing a HackerOne signal requirement on the public program. Researchers who don’t yet meet the signal threshold will have a limited number of allowed submissions while they establish a track record.

This isn’t a wall against new researchers. HackerOne’s platform gives researchers who don’t meet the threshold up to four initial submissions, which is enough runway for a newcomer with a genuine finding to demonstrate their skills. We want to remain accessible to the full security research community; we just need a baseline that keeps the program workable for everyone.

What stays the same

Our commitment to rewarding real security research isn’t changing. We’ll continue to pay out quickly, communicate clearly, and treat researchers as the partners they are.

Reports submitted before these changes take effect will be honored under the previous bounty structure. We’re grandfathering the backlog so that only reports made on or after July 27, 2026 will be assessed with the new structure.

Looking ahead

This is one part of the broader evolution we’re working through. Alongside the bounty restructuring and the VIP program, we’re investing in faster response times, clearer severity reasoning, and more community engagement. Great working relationships are built on more than a pay table. You can engage directly with us at conferences like DEFCON and you’ll hear from us through ongoing outreach. We look forward to joining the researcher community at security conferences, building relationships, and continuing to explore ways to make our bug bounty program one that rewards the kind of deep, thoughtful research we care about most.

The security research community is one of GitHub’s greatest assets. These changes are meant to honor them. We want to build a program that attracts the research we value, creates an experience that reflects how seriously we take this work, and upholds the trust researchers place in us every time they submit a report.

We’ll see you out there, and happy hacking!

Written by

Catherine Cassell

Product Security Engineer

Related posts

How GitHub gave every repository a durable owner

GitHub had over 14,000 repositories. Fewer than half had clear ownership. Here’s how we gave every active repository a validated owner in under 45 days, archived the rest, and made ownership the foundation for everything that followed.

Explore more from GitHub

Docs

Docs

Everything you need to master GitHub, all in one place.

Go to Docs

GitHub

GitHub

Build what’s next on GitHub, the place for anyone from anywhere to build anything.

Start building

Customer stories

Customer stories

Meet the companies and engineering teams that build with GitHub.

Learn more

GitHub Universe 2026

GitHub Universe 2026

Join us October 28-29 in San Francisco or online for GitHub Universe, our flagship developer event uniting people, agents, and the world’s code.

Register now