GitHub宣布对其漏洞赏金计划进行重组,采取多项改革措施以提升报告质量[1]。
新政策引入永久VIP项目,以表彰高质量的安全研究人员[1]。符合VIP资格的条件包括至少一个关键发现、或两个高级发现、或四个中级发现、或七个低级发现[1]。
赏金支付结构也将随之调整,从原有的金额区间制改为固定金额[1]。此外,GitHub实施HackerOne信号要求,未达阈值的研究人员最多可提交4份初始报告,旨在减少低质量和AI生成的报告[1]。
新政策自2026年7月27日起生效[1]。在此日期之前提交的报告将继续按原有赏金结构处理[1]。
GitHub has announced a comprehensive restructuring of its bug bounty program, introducing a permanent VIP tier to recognize top-performing researchers while implementing stricter quality controls. [1]
The revamped program establishes a new VIP classification with specific eligibility thresholds: researchers must have identified at least one critical vulnerability, or two high-severity findings, or four medium-severity findings, or seven low-severity findings to qualify. [1]
Under the revised compensation structure, bounty amounts will be fixed figures rather than ranges. [1] Additionally, GitHub is implementing HackerOne signal requirements to filter out low-quality and AI-generated submissions; researchers who have not yet met the necessary threshold may submit up to four initial reports. [1]
The new policy takes effect on July 27, 2026. [1] Reports submitted prior to this date will continue to be processed under the previous bounty structure. [1]