Policy and restrictions
Protect others’ information; no social engineering, physical attacks, volumetric disruption, spam or excessive automation. Product-specific exclusions apply; coordinate disclosure until a fix is public.
Eligibility and submission status
First reproducible report; current employees/contractors and those within six months of leaving are excluded. Sanctions and legal requirements apply.
Official policy reviewed, but a live submission-acceptance indicator was not separately established.
Advertised rewards
Public-program guidelines list $250 low, $2,000 medium, $5,000 high and $10,000 critical. Defense-in-depth reports receive merchandise. Private-program figures are separate.
Advertised schedules and exceptional ceilings are not individual award evidence.
Published scope snapshot
Captured 2026-10-03. Check the current policy for changes before participating.
| Asset | Type | Group / eligibility |
|---|---|---|
github.com and its subdomains | domain_pattern | |
*.githubassets.com | domain_pattern | |
*.githubusercontent.com | domain_pattern | |
*.githubapp.com | domain_pattern | |
*.githubwebhooks.net | domain_pattern | |
*.github.net | domain_pattern | |
*.npmjs.com | domain_pattern | |
*.npmjs.org | domain_pattern | |
GitHub.com | product | Target directory |
GitHub API | product | Target directory |
GitHub CSP | product | Target directory |
GitHub Actions | product | Target directory |
GitHub Pages | product | Target directory |
GitHub Gist | product | Target directory |
GitHub Enterprise Server | product | Target directory |
GitHub Enterprise Cloud | product | Target directory |
Dependabot | product | Target directory |
GitHub Desktop | product | Target directory |
GitHub Mobile | product | Target directory |
GitHub CLI | product | Target directory |
GitHub Copilot App | product | Target directory |
GitHub Codespaces | product | Target directory |
GitHub Copilot | product | Target directory |
GitHub Education | product | Target directory |
GitHub Credentials | product | Target directory |
npm Registry | product | Target directory |
npm CLI | product | Target directory |
| Asset | Type | Group / eligibility |
|---|---|---|
blog.github.com | domain | |
community.github.com | domain | |
email.enterprise.github.com | domain | |
email.finance.github.com | domain | |
email.staging.finance.github.com | domain | |
email.support.github.com | domain | |
email.verify.github.com | domain | |
google7650dcf6146f04d8.github.com | domain | |
k1._domainkey.github.com | domain | |
k1._domainkey.mcmail.github.com | domain | |
mcmail.github.com | domain | |
resources.github.com | domain | |
*.resources.github.com | domain_pattern | |
sgmail.github.com | domain | |
*.sgmail.github.com | domain_pattern | |
shop.github.com | domain | |
smtp.github.com | domain | |
*.smtp.github.com | domain_pattern | |
livesend.github.com | domain | |
atom-io.githubapp.com | domain | |
atom-io-staging.githubapp.com | domain | |
email.enterprise-staging.githubapp.com | domain | |
email.haystack.githubapp.com | domain | |
reply.githubapp.com | domain |
Review limitations
- Official GitHub-hosted rules were retrieved; the HackerOne submission page required JavaScript and was not independently reviewed as policy evidence.
- Published reward amounts are discretionary guidelines, not fixed payouts.
- Dollar signs are shown without an explicit ISO currency code in reviewed pages; currency-normalized bounds remain null.
- No dedicated policy change-log URL was verified.
- Scope and exclusion pages were freshly reviewed; reward guidelines retain their earlier retrieval date. Product-specific policy subpages and full revision history were not exhaustively reviewed.
- High-level coverage and exclusion context only. Asset inventories and testing instructions are omitted; current official terms prevail and this record grants no authorization.
Sources and provenance
- GitHub Bug Bounty GitHub · reviewed 2026-10-03
- GitHub reward guidelines GitHub · reviewed 2026-10-02
- GitHub program rules GitHub · reviewed 2026-10-03
- GitHub ineligible submissions GitHub · reviewed 2026-10-03
- GitHub high-level program scope policy GitHub · reviewed 2026-10-03
- GitHub Bug Bounty scope GitHub · reviewed 2026-10-03
- GitHub Bug Bounty target directory GitHub · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.