Node.js HackerOne
Security reports for the Node.js runtime go through the HackerOne program.
Tags: vendor, hackerone, opensource
- Program model
- Vendor on HackerOne
- Regions
- Global
- Payout
- Varies by program
Specialties: opensource, runtime
How to approach it
Scope first, and confirm whether rewards are currently funded. The project has said bounty money can be paused while HackerOne stays the reporting channel.
- Read the Node.js threat model before you file a runtime issue.
- Third-party npm packages are not this program. Report those to the maintainer.