What this record establishes
Reviewed policy
An individually reviewed public policy is linked to this program page.
Read the reviewed policy profile →
Directory row 368; Active program checkbox checked; Bounties minimum displayed -. Program type unknown: no positive displayed minimum; absence or zero does not establish VDP. Policy and live submission availability unverified.
Published asset scope
Snapshot captured 2026-10-03. Scope status: Captured.
| Asset | Type | Group / eligibility |
|---|---|---|
https://github.com/curl/curl | SOURCE_CODE | Bounty eligible: No |
| Asset | Type | Group / eligibility |
|---|---|---|
| No rows captured. This does not establish that the program has no assets or restrictions. | ||
Capture limits
- The HackerOne policy displays May 13, 2026. Its updates page contains no updates; revision archives were not reviewed.
- The January 26 announcement directed reports to GitHub or email. The current project policy instead directs them to HackerOne and rejects email reporting; browser review confirmed that discrepancy.
- No age or residency rule was established. No account, submission or target interaction occurred. Full live terms prevail; this summary grants no authorization.
- Only the project disclosure policy was refreshed for scope context; platform policy, updates and closure notices retain their earlier retrieval dates. No overall revision date or exhaustive exclusion coverage is asserted.
Live policy and platform eligibility still require review.
Sources and collection identity
- Official program page Primary source · reviewed 2026-10-03
Appears in Discovery, Profile. No identity match is inferred from a shared company name.