Home / Companies / GitHub / Blog / Post Details
Content Deep Dive

GitHub Security Bug Bounty program turns one

Blog post from GitHub

Post Details
Company
Date Published
Author
Ben Toews
Word Count
264
Company Posts That Month
13
Language
English
Hacker News Points
-
Post removed?
No
Summary

GitHub's Security Bug Bounty program, launched a year ago, has successfully led to the identification and resolution of 73 previously unknown security vulnerabilities in their applications, thanks to global researchers. Out of 1,920 submissions, 869 were significant enough to warrant further review, addressing vulnerabilities across nine OWASP top 10 classifications. Notably, 33 researchers collectively earned $50,100 for reporting 57 medium to high-risk vulnerabilities, with standout contributions from researchers like @adob and @joernchen, who discovered complex exploits involving cross-site scripting and remote command execution. As the program enters its second year, GitHub is increasing the maximum bounty payout from $5,000 to $10,000, encouraging further participation and inviting submissions of newfound vulnerabilities while providing ongoing updates via their @GitHubSecurity account.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.