Next chapter: Restructuring GitHub’s bug bounty program
dev_tools
Per the GitHub Blog, GitHub is restructuring its bug bounty program to reward deep research over high submission volume. They're launching a permanent VIP program for researchers who consistently deliver high-impact findings—one critical, two high, four medium, or seven low severity discoveries earn entry. VIP members receive significantly higher payouts, including thirty thousand dollars or more for critical vulnerabilities, plus faster response times and closer partnerships with GitHub's security team. For the public program, GitHub is moving to static payouts: two hundred fifty dollars for low severity, two thousand for medium, five thousand for high, and ten thousand for critical. The company is also implementing a signal requirement to filter out low-effort and AI-generated reports, though newcomers still get four initial submissions to build their track record. The shift reflects a core philosophy: rewarding the kind of thorough research that actually protects the platform.
Source: https://github.blog/security/next-chapter-restructuring-g...
Listen to this story
Hear this and more stories in a personalized audio briefing.
Open The Chonkerton