logoalt Hacker News

dinkelbergtoday at 2:54 AM2 repliesview on HN

So if the "wrong" person finds a critical vulnerability in GitHub, the payout is capped at $10,000. Might reduce the likelihood of it being submitted to the bug bounty program.


Replies

toomuchtodotoday at 3:27 AM

It might, but as someone who has to review public vulnerability reports for a much less popular website, I completely understand why they’re building a vouch program to dissuade slop reports. One would presume their internal team is using frontier models for red team agent scanning against potential attack surface, and so this is a potential risk they’re willing to take.

Tragedy of the commons that someone who hasn’t passed the filter yet might have their payout limited.

Vouch - https://news.ycombinator.com/item?id=46930961 - February 2026 (486 comments)

show 2 replies