GitLab Bug Bounty Program policy updates
Blog post from GitLab
GitLab's HackerOne Bug Bounty program, initially launched in 2018, has been updated to enhance transparency, improve testing guidance, and refine the scope of vulnerabilities in response to feedback from the security research community. These updates emphasize the use of local testing environments through the GitLab Development Kit (GDK) to protect both researchers and production infrastructure, with specific recommendations for testing denial-of-service (DoS) impacts and vulnerabilities requiring production architecture. The scope has been clarified to exclude standalone prompt injection and general information gathering, while still including privacy breaches and certain application layer DoS vulnerabilities. A transition period with a 7-day grace period is provided for researchers with active investigations under the previous policy. GitLab remains committed to transparency, safety, and fairness by setting clearer boundaries, protecting systems, and ensuring consistent evaluation standards, which supports program sustainability and focuses resources on high-impact security issues. New researchers are encouraged to visit the HackerOne program page, set up local testing, and review the full policy for detailed guidelines, while the security research community is thanked for their ongoing contributions to maintaining GitLab's security.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.