3 min Security

GitHub revamps bug bounty program and emphasizes quality

GitHub revamps bug bounty program and emphasizes quality

GitHub is implementing a major overhaul of its bug bounty program. The platform is introducing a closed VIP program for experienced security researchers, reducing rewards for the public program, and taking steps to curb the influx of AI-generated reports.

According to GitHub, the existing program has become increasingly difficult to manage over the past few years. The number of submitted vulnerability reports has risen sharply, partly due to the rise of AI-assisted security research. As a result, it is taking more and more time to distinguish relevant reports from those with little or no added value.

For this reason, the company has decided to allocate more resources to researchers who demonstrably report valuable vulnerabilities, rather than rewarding a growing number of reports from a broader group of participants.

Exclusive VIP program

The most significant change is the introduction of a permanent, invitation-only VIP program. Researchers who repeatedly report high-impact vulnerabilities gain access to this exclusive program. They receive higher rewards, faster feedback, and more direct contact with GitHub’s security engineering team.

The maximum reward within the VIP program is over $30,000 for critical vulnerabilities. Even for reports with a lower severity, the rewards are significantly higher than in the public program.

Admission is based on past performance. For example, researchers must have submitted one critical vulnerability, two severe vulnerabilities, or multiple lower-risk reports before they are eligible.

Significant reduction in public rewards

At the same time, GitHub is significantly reducing the rewards within its public bug bounty program. The maximum reward for a critical vulnerability has been reduced from $30,000 to $10,000. For high-severity vulnerabilities, the maximum payout is being reduced from $20,000 to $5,000. Rewards for medium- and low-severity reports are also being lowered.

In addition, GitHub is moving away from variable reward ranges. From now on, each severity level will have a single fixed payout amount. According to the company, this provides greater clarity for researchers and reduces disputes over the final reward. An additional bonus remains possible for exceptional reports.

According to GitHub, the public program will continue to serve as a gateway for researchers who want to prove themselves and eventually advance to the VIP program.

AI reports create additional workload

GitHub is also taking measures to reduce the number of low-quality reports. A so-called “signal requirement” is being introduced via HackerOne. Researchers who have not yet established a reliable track record will initially be allowed to submit only a limited number of reports.

Although GitHub does not explicitly ban AI, the company cites the growth of AI-generated reports as a key reason for tightening its rules. The measure is intended to prevent security teams from spending excessive time on automatically generated reports that contain little new information.

New researchers are still welcome. HackerOne allows participants who do not yet meet the quality requirements to submit up to 4 initial reports, giving them the opportunity to demonstrate the value of their findings.

Part of a broader shift in strategy

The revised reward structure takes effect on July 27. Reports submitted before that date will still be processed under the old terms.

The reform follows earlier measures GitHub has already taken this year to improve the quality of bug reports. In doing so, the company warned researchers not to flood the platform with AI-generated reports. According to The Register, the new structure is part of a broader strategy in which GitHub aims to reduce the number of reports and focus on those that actually contribute to the platform’s security.