Policy and restrictions
Privacy violations, disruption, unverified automated reports and third-party/customer installations are excluded. A shared mitigation generally receives one award; GitLab determines severity and payment.
Eligibility and submission status
Current employees are excluded; former employees, immediate family and potentially conflicted associates receive additional review. Reports require verifiable evidence.
An enabled submission link and no pause notice were observed, but submission acceptance was not tested or explicitly stated.
Advertised rewards
Advertised ranges: Low $100–$750; Medium $1,000–$2,500; High $5,000–$15,000; Critical $20,000–$35,000. Business impact and reduced category schedules affect awards.
Advertised schedules and exceptional ceilings are not individual award evidence.
Published scope snapshot
Captured 2026-10-03. Check the current policy for changes before participating.
| Asset | Type | Group / eligibility |
|---|---|---|
*.gitlab.net | WILDCARD | Bounty eligible: Yes |
*.gitlab.org | WILDCARD | Bounty eligible: Yes |
*.gitlap.com | WILDCARD | Bounty eligible: Yes |
customers.gitlab.com | URL | Bounty eligible: Yes |
registry.gitlab.com | URL | Bounty eligible: Yes |
gitlab.com | URL | Bounty eligible: Yes |
about.gitlab.com | URL | Bounty eligible: Yes |
docs.gitlab.com | URL | Bounty eligible: Yes |
design.gitlab.com | URL | Bounty eligible: Yes |
advisories.gitlab.com | URL | Bounty eligible: Yes |
https://gitlab.com/gitlab-org/gitlab | SOURCE_CODE | Bounty eligible: Yes |
https://gitlab.com/gitlab-org/gitlab-runner | SOURCE_CODE | Bounty eligible: Yes |
https://gitlab.com/gitlab-org/gitaly | SOURCE_CODE | Bounty eligible: Yes |
https://gitlab.com/gitlab-org/gitlab-pages | SOURCE_CODE | Bounty eligible: Yes |
https://gitlab.com/gitlab-org/gitlab-shell | SOURCE_CODE | Bounty eligible: Yes |
https://gitlab.com/gitlab-org/gitlab-vscode-extension | SOURCE_CODE | Bounty eligible: Yes |
Your Own GitLab Instance | OTHER | Bounty eligible: Yes |
Other non-production infrastructure | OTHER | Bounty eligible: Yes |
GitLab for Jira Cloud | OTHER | Bounty eligible: Yes |
| Asset | Type | Group / eligibility |
|---|---|---|
*.gitlab.cn | WILDCARD | Bounty eligible: No |
*.runway.gitlab.net | WILDCARD | Bounty eligible: No |
*.gitlab-private.org | WILDCARD | Bounty eligible: No |
*.service-now.com | WILDCARD | Bounty eligible: No |
dashboards.gitlab.com | URL | Bounty eligible: No |
alerts.gitlab.com | URL | Bounty eligible: No |
support.gitlab.com | URL | Bounty eligible: No |
shop.gitlab.com | URL | Bounty eligible: No |
forum.gitlab.com | URL | Bounty eligible: No |
status.gitlab.com | URL | Bounty eligible: No |
partners.gitlab.com | URL | Bounty eligible: No |
aptly.gitlab.com | URL | Bounty eligible: No |
translate.gitlab.com | URL | Bounty eligible: No |
federal-support.gitlab.com | URL | Bounty eligible: No |
us-federal-gitlab.com | URL | Bounty eligible: No |
ir.gitlab.com | URL | Bounty eligible: No |
levelup.gitlab.com | URL | Bounty eligible: No |
gitlab.biterg.io | URL | Bounty eligible: No |
gitlabsandbox.net | URL | Bounty eligible: No |
gitlabdemo.cloud | URL | Bounty eligible: No |
gitlabtraining.cloud | URL | Bounty eligible: No |
packages.gitlab.com | URL | Bounty eligible: No |
https://gitlab.com/gitlab-org/cli/ | SOURCE_CODE | Bounty eligible: No |
https://gitlab.com/gitlab-org/opstrace/opstrace-ui | SOURCE_CODE | Bounty eligible: No |
https://gitlab.com/gitlab-org/opstrace/opstrace | SOURCE_CODE | Bounty eligible: No |
Review limitations
- Browser-rendered policy reviewed; static retrieval returned a JavaScript placeholder.
- Policy updated July 21, 2026; the displayed reward-table date is November 22, 2021. Its age is retained rather than assumed obsolete.
- Only dollar signs appear; ISO currency and normalized bounds remain null. Full live policy includes additional conditions.
Sources and provenance
- GitLab Bug Bounty | Bounty Policy | HackerOne GitLab / HackerOne · reviewed 2026-10-02
- Published HackerOne structured scope GitLab · reviewed 2026-10-03
Record reviewed 2026-10-02. Snapshot 53796974ace8. Open the complete JSON contract.