vulns.co
/
GKData.io MCP

HackerOne · 2 min read

GitLab

Paid Bounty

Open current program Reviewed policy

What this record establishes

Reviewed policy

An individually reviewed public policy is linked to this program page.

Read the reviewed policy profile →

Directory row 425; Active program checkbox checked; Bounties minimum displayed $100. Positive displayed minimum supports paid bounty listing. Policy and live submission availability unverified.

Published asset scope

Snapshot captured 2026-10-03. Scope status: Captured.

In scope · 19 published rows
AssetTypeGroup / eligibility
*.gitlab.netWILDCARDBounty eligible: Yes
*.gitlab.orgWILDCARDBounty eligible: Yes
*.gitlap.comWILDCARDBounty eligible: Yes
customers.gitlab.comURLBounty eligible: Yes
registry.gitlab.comURLBounty eligible: Yes
gitlab.comURLBounty eligible: Yes
about.gitlab.comURLBounty eligible: Yes
docs.gitlab.comURLBounty eligible: Yes
design.gitlab.comURLBounty eligible: Yes
advisories.gitlab.comURLBounty eligible: Yes
https://gitlab.com/gitlab-org/gitlabSOURCE_CODEBounty eligible: Yes
https://gitlab.com/gitlab-org/gitlab-runnerSOURCE_CODEBounty eligible: Yes
https://gitlab.com/gitlab-org/gitalySOURCE_CODEBounty eligible: Yes
https://gitlab.com/gitlab-org/gitlab-pagesSOURCE_CODEBounty eligible: Yes
https://gitlab.com/gitlab-org/gitlab-shellSOURCE_CODEBounty eligible: Yes
https://gitlab.com/gitlab-org/gitlab-vscode-extensionSOURCE_CODEBounty eligible: Yes
Your Own GitLab InstanceOTHERBounty eligible: Yes
Other non-production infrastructureOTHERBounty eligible: Yes
GitLab for Jira CloudOTHERBounty eligible: Yes
Out of scope · 25 published rows
AssetTypeGroup / eligibility
*.gitlab.cnWILDCARDBounty eligible: No
*.runway.gitlab.netWILDCARDBounty eligible: No
*.gitlab-private.orgWILDCARDBounty eligible: No
*.service-now.comWILDCARDBounty eligible: No
dashboards.gitlab.comURLBounty eligible: No
alerts.gitlab.comURLBounty eligible: No
support.gitlab.comURLBounty eligible: No
shop.gitlab.comURLBounty eligible: No
forum.gitlab.comURLBounty eligible: No
status.gitlab.comURLBounty eligible: No
partners.gitlab.comURLBounty eligible: No
aptly.gitlab.comURLBounty eligible: No
translate.gitlab.comURLBounty eligible: No
federal-support.gitlab.comURLBounty eligible: No
us-federal-gitlab.comURLBounty eligible: No
ir.gitlab.comURLBounty eligible: No
levelup.gitlab.comURLBounty eligible: No
gitlab.biterg.ioURLBounty eligible: No
gitlabsandbox.netURLBounty eligible: No
gitlabdemo.cloudURLBounty eligible: No
gitlabtraining.cloudURLBounty eligible: No
packages.gitlab.comURLBounty eligible: No
https://gitlab.com/gitlab-org/cli/SOURCE_CODEBounty eligible: No
https://gitlab.com/gitlab-org/opstrace/opstrace-uiSOURCE_CODEBounty eligible: No
https://gitlab.com/gitlab-org/opstrace/opstraceSOURCE_CODEBounty eligible: No

Capture limits

  • Browser-rendered policy reviewed; static retrieval returned a JavaScript placeholder.
  • Policy updated July 21, 2026; the displayed reward-table date is November 22, 2021. Its age is retained rather than assumed obsolete.
  • Only dollar signs appear; ISO currency and normalized bounds remain null. Full live policy includes additional conditions.
  • Published structured-scope rows were captured. Submission eligibility and bounty eligibility differ; program policy text may add restrictions.

Live policy and platform eligibility still require review.

Sources and collection identity

  1. Official program page Primary source · reviewed 2026-10-03
  2. Published scope source Primary source · reviewed 2026-10-03

Appears in Discovery, Bounty, Profile. No identity match is inferred from a shared company name.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software