vulns.co
/
GKData.io MCP

GitHub · 3 min read

GitHub Bug Bounty

GitHub · HackerOne submission channel. Policy reviewed 2026-10-03. Live terms govern participation.

Open current policy Reviewed policy

Policy and restrictions

Protect others’ information; no social engineering, physical attacks, volumetric disruption, spam or excessive automation. Product-specific exclusions apply; coordinate disclosure until a fix is public.

Eligibility and submission status

First reproducible report; current employees/contractors and those within six months of leaving are excluded. Sanctions and legal requirements apply.

Official policy reviewed, but a live submission-acceptance indicator was not separately established.

Advertised rewards

Public-program guidelines list $250 low, $2,000 medium, $5,000 high and $10,000 critical. Defense-in-depth reports receive merchandise. Private-program figures are separate.

Advertised schedules and exceptional ceilings are not individual award evidence.

Published scope snapshot

Captured 2026-10-03. Check the current policy for changes before participating.

In scope · 27 published rows
AssetTypeGroup / eligibility
github.com and its subdomainsdomain_pattern
*.githubassets.comdomain_pattern
*.githubusercontent.comdomain_pattern
*.githubapp.comdomain_pattern
*.githubwebhooks.netdomain_pattern
*.github.netdomain_pattern
*.npmjs.comdomain_pattern
*.npmjs.orgdomain_pattern
GitHub.comproductTarget directory
GitHub APIproductTarget directory
GitHub CSPproductTarget directory
GitHub ActionsproductTarget directory
GitHub PagesproductTarget directory
GitHub GistproductTarget directory
GitHub Enterprise ServerproductTarget directory
GitHub Enterprise CloudproductTarget directory
DependabotproductTarget directory
GitHub DesktopproductTarget directory
GitHub MobileproductTarget directory
GitHub CLIproductTarget directory
GitHub Copilot AppproductTarget directory
GitHub CodespacesproductTarget directory
GitHub CopilotproductTarget directory
GitHub EducationproductTarget directory
GitHub CredentialsproductTarget directory
npm RegistryproductTarget directory
npm CLIproductTarget directory
Out of scope · 24 published rows
AssetTypeGroup / eligibility
blog.github.comdomain
community.github.comdomain
email.enterprise.github.comdomain
email.finance.github.comdomain
email.staging.finance.github.comdomain
email.support.github.comdomain
email.verify.github.comdomain
google7650dcf6146f04d8.github.comdomain
k1._domainkey.github.comdomain
k1._domainkey.mcmail.github.comdomain
mcmail.github.comdomain
resources.github.comdomain
*.resources.github.comdomain_pattern
sgmail.github.comdomain
*.sgmail.github.comdomain_pattern
shop.github.comdomain
smtp.github.comdomain
*.smtp.github.comdomain_pattern
livesend.github.comdomain
atom-io.githubapp.comdomain
atom-io-staging.githubapp.comdomain
email.enterprise-staging.githubapp.comdomain
email.haystack.githubapp.comdomain
reply.githubapp.comdomain

Review limitations

  • Official GitHub-hosted rules were retrieved; the HackerOne submission page required JavaScript and was not independently reviewed as policy evidence.
  • Published reward amounts are discretionary guidelines, not fixed payouts.
  • Dollar signs are shown without an explicit ISO currency code in reviewed pages; currency-normalized bounds remain null.
  • No dedicated policy change-log URL was verified.
  • Scope and exclusion pages were freshly reviewed; reward guidelines retain their earlier retrieval date. Product-specific policy subpages and full revision history were not exhaustively reviewed.
  • High-level coverage and exclusion context only. Asset inventories and testing instructions are omitted; current official terms prevail and this record grants no authorization.

Sources and provenance

  1. GitHub Bug Bounty GitHub · reviewed 2026-10-03
  2. GitHub reward guidelines GitHub · reviewed 2026-10-02
  3. GitHub program rules GitHub · reviewed 2026-10-03
  4. GitHub ineligible submissions GitHub · reviewed 2026-10-03
  5. GitHub high-level program scope policy GitHub · reviewed 2026-10-03
  6. GitHub Bug Bounty scope GitHub · reviewed 2026-10-03
  7. GitHub Bug Bounty target directory GitHub · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software