Home / Companies / GitLab / Blog / Post Details
Content Deep Dive

GitLab's HackerOne Bug Bounty Program is public today

Blog post from GitLab

Post Details
Company
Date Published
Author
Kathy Wang
Word Count
262
Company Posts That Month
16
Language
English
Hacker News Points
-
Post removed?
No
Summary

The announcement highlights the transition of a bug bounty program to a public format on HackerOne, following its initial private inception in December 2017. Over $200,000 in bounties have been awarded for nearly 200 reported vulnerabilities, and security automation has significantly reduced the first response time to new findings from over 48 hours to just seven. The program has achieved a mean time to mitigation of under 30 days for critical security issues, with goals to reduce this metric for medium-high issues to under 60 days. The public program aims to engage the hacker community by rewarding them directly for reporting security vulnerabilities, and it acknowledges the contributions of top community members like ngalog, jobert, and fransrosen. The announcement also mentions plans for further expansion in 2019 and beyond, inviting more participation from the public.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.