github

Next chapter: Restructuring GitHub’s bug bounty program (opens in new tab)

GitHub is restructuring its bug bounty program to prioritize high-quality, high-impact security research over report volume. The changes introduce a permanent VIP program with higher rewards and faster support, reduce and simplify public-program payouts, and add submission limits for researchers without an established track record. Reports submitted before July 27, 2026 will remain under the previous terms.

Permanent VIP program for top researchers

GitHub is creating a private, invite-only program for researchers who consistently produce valuable findings.

  • VIP researchers receive:
    • Higher payouts
    • Faster response times
    • Closer collaboration with GitHub’s security engineering team
  • VIP bounty payouts are:
    • Low: $1,000
    • Medium: $7,500
    • High: $20,000
    • Critical: $30,000+
  • Researchers can qualify by achieving at least one of the following:
    • One critical finding
    • Two high-severity findings
    • Four medium-severity findings
    • Seven low-severity findings
  • The program emphasizes quality and impact rather than the number of submissions.

Restructured public bounty payouts

GitHub is replacing variable payout ranges with fixed amounts to make rewards more predictable and reduce administrative overhead.

  • New public-program payouts:
    • Low: $250
    • Medium: $2,000
    • High: $5,000
    • Critical: $10,000
  • GitHub may still provide discretionary bonuses for exceptional work.
  • The public program will remain an entry point for new researchers and a pathway into the VIP program.

Higher submission standards

To address increasing report volume, including low-effort and AI-generated submissions, GitHub is adding a HackerOne signal requirement.

  • Researchers below the required signal threshold will have a limited number of submissions.
  • New researchers can make up to four initial submissions while establishing credibility.
  • The goal is to reduce noise without excluding legitimate newcomers.

Existing commitments and transition period

GitHub says it will continue paying quickly, communicating clearly, and treating researchers as security partners.

  • Reports submitted before the changes take effect will follow the old bounty structure.
  • Reports submitted on or after July 27, 2026 will use the new rules.
  • GitHub also plans to improve response times, severity explanations, and community engagement through conferences and outreach.

The restructuring is designed to make GitHub’s bug bounty program more sustainable while directing greater rewards and attention toward researchers who deliver deep, thoughtful security work.