HeadlinesBriefing favicon HeadlinesBriefing.com

GitHub Restructures Bug Bounty Program

Hacker News •
×

The security research community makes GitHub safer for everyone. For more than a decade, researchers worldwide have helped us find and fix vulnerabilities before exploitation, and we’ve worked hard to be a program worth their time. Today, we share meaningful changes after months of reflection, industry analysis, and focus on researcher experience. The queue is growing, and we’ve adjusted to accommodate new researchers and the accelerating work of our existing partners. Our changes aim to reduce noise, focus on signal, and build a rewarding experience for serious researchers.

We’re formalizing a permanent private, invite‑only VIP program for qualified researchers consistently delivering high‑quality, high‑impact work. VIP researchers receive higher payouts, faster response times, and a closer partnership with our security engineering team. The goal is to create a space where those who invest deeply in understanding GitHub can work with us directly. Bounty table: Low $1,000, Medium $7,500, High $20,000, Critical $30,000+. To qualify, researchers must meet criteria such as one critical finding, two high findings, four medium findings, or seven low findings.

We’re also adjusting our public program rates to emphasize quality over quantity. Payouts are now static: Low $250, Medium $2,000, High $5,000, Critical $10,000. This clarity removes uncertainty and overhead. We’ll still award discretionary bonuses for exceptional work. Additionally, we’re implementing a signal requirement on Hacker One; researchers below the threshold have only four initial submissions to establish a track record. This is not a wall for new researchers but a baseline to keep the program workable.

Our commitment to rewarding real research remains unchanged—we’ll keep quick payouts, clear communication, and treat researchers as partners. Reports before July 27, 2026 will honor the old structure. Looking ahead, we’ll invest in faster response times, clearer severity reasoning, and more community engagement, including DEFCON and other conferences. The security research community is GitHub’s greatest asset; these changes honor them and aim to attract the research we value.