A Decade of the GitHub Security Bug Bounty
The GitHub Security Bug Bounty program has just crossed a notable threshold: ten years of operation. Over that period, the structure and rewards have changed dramatically, but the core objective—leveraging outside researchers to find vulnerabilities through responsible disclosure and rewarding that effort—has remained consistent.
The program’s origins date to 2014, when GitHub first opened the initiative to engage more directly with the security research community. At the time, the company acknowledged that while it works continuously to secure its services, some vulnerabilities are inherently difficult to track down, and extra eyes help. The scope initially covered only a limited subset of products and has expanded steadily since.
A few milestones stand out across the decade:
- 2016: After two years of running reports through a homegrown email system, GitHub moved the program to HackerOne.
- 2017: Bounty amounts were increased, and GitHub took part in Hack the World, offering double reputation points on HackerOne for valid findings.
- 2018: A Legal Safe Harbor policy was introduced to protect researchers from legal consequences for good-faith efforts to comply with the bounty policy, removing a barrier to participation.
- 2019: Submissions rose 40%, and the scope expanded to include newer products such as GitHub Actions and GitHub Mobile.
- 2020: GitHub earned a place on HackerOne’s list of top ten bounty programs, judged on cumulative bounties, time to payout, and report resolution metrics.
- 2021: GitHub doubled the total of researchers’ donated bounties on top of over $64,000, pushing the program’s charitable contributions past $100,000. Beneficiaries included Cancer Research UK, the GiveWell Maximum Impact Fund, the Greater Pittsburgh Community Food Bank, and Numfocus.
- 2022: The GitHub Bug Bounty swag store launched, letting researchers redeem points for apparel and gear alongside cash payouts.
- 2023: The program issued its largest single reward to date at $75,000—a number worth comparing to the roughly $50,000 total paid out in the entire first year.

By the end of 2023, cumulative payouts had exceeded $4 million.
Follow-up Report: 2023 in Review
Looking closer at the most recent year, GitHub’s stated objectives were to increase transparency in communications and rewards, grow both its public and private programs, and build a stronger community presence. The practical results broke down along those lines.
Transparency and Communication
The project focused on parsing recurring feedback themes and turning them into actionable changes. One major experiment was the introduction of limited disclosure for HackerOne reports, and the team credits those learnings with shaping next steps. On the interpersonal side, the program aimed to make responses more detailed and clear—an acknowledgment that bounty work is fundamentally human-to-human.
Program Growth
The public scope is kept fresh with new GitHub features as they come online, and 2023 saw additions such as GitHub Copilot and Copilot Chat. Private engagements were also run with the program’s Hacktocats VIP group, covering areas like PATs v2 via GraphQL and Copilot Chat, giving engineers a chance to sort out issues with input from researchers before a wider release. Payout competitiveness also remained top-of-mind, underscored by that record $75,000 bounty.


Community Presence
The team put emphasis on being visible at security events across the US, Canada, and Argentina, giving talks and hosting meetups. Appearances spanned several conferences: a walkthrough of the “Life of a Bug” at Bsides SF, a discussion on building effective bounty programs at DEFCON, and a detailed look at GitHub’s program mechanics at NorthSec. Beyond conference circuits, GitHub collaborated with Capital One and HackerOne to launch Glass Firewall, a conference designed to support women in security research, with a stated goal of “breaking bytes and barriers.”
Upcoming Work
For the next phase, GitHub outlines several process-oriented improvements. Priorities include refining how payouts are handled on validation, moving toward the next stage of public disclosure, applying more consistent rules for private bounties, and offering exclusive training and opportunities for its VIP participants.
Current and prospective researchers can consult the program’s website for the latest scope, rules, and reward details.



