What this record establishes
Reviewed policy
An individually reviewed public policy is linked to this program page.
Read the reviewed policy profile →
Directory row 423; Active program checkbox checked; Bounties minimum displayed $250. Positive displayed minimum supports paid bounty listing. Policy and live submission availability unverified.
Published asset scope
Snapshot captured 2026-10-03. Scope status: Captured.
| Asset | Type | Group / eligibility |
|---|---|---|
github.com and its subdomains | domain_pattern | |
*.githubassets.com | domain_pattern | |
*.githubusercontent.com | domain_pattern | |
*.githubapp.com | domain_pattern | |
*.githubwebhooks.net | domain_pattern | |
*.github.net | domain_pattern | |
*.npmjs.com | domain_pattern | |
*.npmjs.org | domain_pattern | |
GitHub.com | product | Target directory |
GitHub API | product | Target directory |
GitHub CSP | product | Target directory |
GitHub Actions | product | Target directory |
GitHub Pages | product | Target directory |
GitHub Gist | product | Target directory |
GitHub Enterprise Server | product | Target directory |
GitHub Enterprise Cloud | product | Target directory |
Dependabot | product | Target directory |
GitHub Desktop | product | Target directory |
GitHub Mobile | product | Target directory |
GitHub CLI | product | Target directory |
GitHub Copilot App | product | Target directory |
GitHub Codespaces | product | Target directory |
GitHub Copilot | product | Target directory |
GitHub Education | product | Target directory |
GitHub Credentials | product | Target directory |
npm Registry | product | Target directory |
npm CLI | product | Target directory |
| Asset | Type | Group / eligibility |
|---|---|---|
blog.github.com | domain | |
community.github.com | domain | |
email.enterprise.github.com | domain | |
email.finance.github.com | domain | |
email.staging.finance.github.com | domain | |
email.support.github.com | domain | |
email.verify.github.com | domain | |
google7650dcf6146f04d8.github.com | domain | |
k1._domainkey.github.com | domain | |
k1._domainkey.mcmail.github.com | domain | |
mcmail.github.com | domain | |
resources.github.com | domain | |
*.resources.github.com | domain_pattern | |
sgmail.github.com | domain | |
*.sgmail.github.com | domain_pattern | |
shop.github.com | domain | |
smtp.github.com | domain | |
*.smtp.github.com | domain_pattern | |
livesend.github.com | domain | |
atom-io.githubapp.com | domain | |
atom-io-staging.githubapp.com | domain | |
email.enterprise-staging.githubapp.com | domain | |
email.haystack.githubapp.com | domain | |
reply.githubapp.com | domain |
Capture limits
- The target directory is a high-level product index; individual target pages may narrow eligibility.
- Unlisted products and GitHub-owned domains are excluded by the official policy; the enumerated exceptions are not the only possible exclusions.
Live policy and platform eligibility still require review.
Sources and collection identity
- Official program page Primary source · reviewed 2026-10-03
- Published scope source Primary source · reviewed 2026-10-03
- Published scope source Primary source · reviewed 2026-10-03
Appears in Discovery, Bounty. No identity match is inferred from a shared company name.