Decoding the world of cybersecurity

GitHub narrows access to its bug bounty

GitHub has lowered public bounty payments while formalising a higher-paying invitation-only programme, citing growing volumes of low-quality and AI-generated vulnerability reports.

GitHub narrows access to its bug bounty
Summary
  • GitHub’s new bounty structure applies to reports submitted from 27 July 2026.
  • Public rewards are lower than VIP rewards, with the largest payments reserved for invited researchers.
  • New researchers receive limited opportunities to establish a submission record before unrestricted access is granted.

GitHub has restructured its security bug bounty programme around an invitation-only group of established researchers, while lowering standard public rewards and limiting unrestricted submissions from newcomers.

The new structure applies to reports filed from 27 July. GitHub says the programme has faced a growing queue, more low-effort submissions, and vulnerability reports created with artificial-intelligence tools that require substantial triage despite containing little or no valid security value.

Researchers admitted to the permanent VIP programme can receive at least $1,000 for a low-severity finding, $7,500 for medium severity, $20,000 for high severity, and $30,000 or more for a critical issue. They will also receive faster responses and closer access to GitHub’s security engineering staff.

The public programme pays $250 for low-severity reports, $2,000 for medium, $5,000 for high, and $10,000 for critical findings. Researchers can qualify for VIP status through a record of accepted submissions, including one critical, two high, four medium, or seven low-severity reports.

GitHub is also requiring sufficient HackerOne signal before allowing unrestricted submission. New researchers without the required standing will receive up to four initial reporting opportunities through which they can establish a record.

Reports submitted before the change will be handled under the previous terms. GitHub’s programme notice also commits the company to faster responses, clearer severity reasoning, and closer engagement with researchers.

A large queue of automated or speculative reports consumes time that could otherwise be spent validating complex vulnerabilities. Generative tools can increase submission volume without increasing useful discovery where the reporter has not reproduced the behaviour, established security impact, or understood the target.

Higher signal comes with a narrower entrance

The two-tier model gives experienced researchers a stronger financial incentive to study GitHub in depth. Complex platform vulnerabilities can require weeks of work, specialised infrastructure, and repeated communication with the vendor, so higher payments and direct engineering contact may support longer investigations.

The difference between public and VIP rewards may also affect who chooses to report. A critical finding submitted by a non-VIP researcher carries one-third of the stated minimum payment available to an invited participant, even where the technical impact is the same.

Independent disclosure programmes benefit from people approaching systems without the assumptions held by internal engineering teams. Concentrating access among a smaller trusted group can improve average report quality, while reducing the range of techniques, professional backgrounds, and geographical perspectives reaching the programme.

GitHub occupies a central position in the software supply chain. Enterprises, public bodies, maintainers, and technology suppliers rely on it for repositories, packages, actions, secrets, automation, and development workflows. A platform vulnerability can consequently affect many organisations that cannot test the hosted service themselves.

Those customers depend on GitHub’s internal assurance, independent research, and disclosure processes to identify defects in infrastructure beyond their direct control. Changes to bounty access therefore form part of third party and platform-risk assessment rather than researcher relations alone.

The programme’s performance can be measured through validation times, the number and severity of accepted findings, disputes over impact, researcher retention, remediation speed, and the rate at which valid newcomers progress into unrestricted reporting.

Using HackerOne reputation as a gate may favour researchers already active on the platform. Technically capable people working outside that ecosystem have fewer opportunities to establish credibility, even where they have identified a valid defect.

GitHub’s changes will reduce some report volume by design. Their effectiveness will depend on whether serious findings move through the programme more quickly without leaving valid reports outside the intake process.

×