Introducing the GitHub Bug Bounty swag store
We’re excited to share the newest addition to our GitHub Bug Bounty Program!
Our bug bounty team has had an exciting year, including celebrating the eighth year of our program, hosting a live hacking event in June, spotlighting one of our hackers for cybersecurity awareness month, and spending more time with our community at events such as DEFCON 30. Along the way, we have captured feedback from participants in our program, and we are very excited to announce that we are introducing our very own swag store!
The addition of the swag store comes from many conversations and feedback on how we can continue to improve our bug bounty program. We learned that not only do our researchers genuinely enjoy receiving swag but they also like to show off their involvement with our bounty program.
The new GitHub Bug Bounty swag store will allow researchers to earn exclusive bug bounty branded swag, as a bonus perk to their earned bounty reward. Through reports, researchers have the ability to receive points that can be redeemed for t-shirts, sweatshirts, stickers, and other cool items. For information about our new store, please visit our bounty store FAQ.
Our partnership with talented security researchers from across the community is pivotal in running a successful bug bounty program, so we thank all who continue to support and participate in our program. Your submissions are greatly valued and impactful to ensuring the safety and security of our products, our users, and the community, and we are excited to introduce even more incentives. For more details regarding the program’s scope, rules, and rewards please visit our website. Happy hacking!
Tags:
Written by
Related posts
What 50 open source projects taught us about security in the AI era
See how the open source projects in Session 4 of the GitHub Secure Open Source Fund combined AI-assisted workflows, maintainer expertise, GitHub security tools, expert guidance, and funding to improve project security.
How we took malware advisories beyond npm
GitHub malware advisories no longer stop at npm. Here’s how we wired OpenSSF’s malicious-packages data into the Advisory Database, and why we built the pipeline paranoid.
Tame Dependabot: Group your updates, slow the cadence, keep security fast
Dependabot keeps your dependencies current, but its defaults can flood your repository with pull requests. Here’s how grouping updates, slowing the cadence, and keeping security fixes fast cut the noise on a Microsoft open source project.