| ▲ | dinkelberg 8 hours ago | ||||||||||||||||||||||||||||||||||||||||||||||
So if the "wrong" person finds a critical vulnerability in GitHub, the payout is capped at $10,000. Might reduce the likelihood of it being submitted to the bug bounty program. | |||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | 7 hours ago | parent | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||
| [deleted] | |||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | toomuchtodo 7 hours ago | parent | prev [-] | ||||||||||||||||||||||||||||||||||||||||||||||
It might, but as someone who has to review public vulnerability reports for a much less popular website, I completely understand why they’re building a vouch program to dissuade slop reports. One would presume their internal team is using frontier models for red team agent scanning against potential attack surface, and so this is a potential risk they’re willing to take. Tragedy of the commons that someone who hasn’t passed the filter yet might have their payout limited. Vouch - https://news.ycombinator.com/item?id=46930961 - February 2026 (486 comments) | |||||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||||