Restructuring GitHub's bug bounty program

(github.blog)

11 points | by soheilpro 1 hour ago

2 comments

  • dinkelberg 57 minutes ago
    So if the "wrong" person finds a critical vulnerability in GitHub, the payout is capped at $10,000. Might reduce the likelihood of it being submitted to the bug bounty program.
    • toomuchtodo 23 minutes ago
      It might, but as someone who has to review public vulnerability reports for a much less popular website, I completely understand why they’re building a vouch program to dissuade slop reports. One would presume their internal team is using frontier models for red team agent scanning against potential attack surface, and so this is a potential risk they’re willing to take.

      Tragedy of the commons that someone who hasn’t passed the filter yet might have their payout limited.

      Vouch - https://news.ycombinator.com/item?id=46930961 - February 2026 (486 comments)

  • Klaster_1 26 minutes ago