Github raises bug bounty prize

Image Credit: Pixabay (Image credit: Image Credit: Geralt / Pixabay)

GitHub is making things easier for researchers looking for bugs on its code-hosting site by removing the cap on its bug bounty program's top payout and offering new legal protections for white hat hackers.

After five years, the Microsoft-owned company has decided to revamp its bug bounty program by providing higher rewards for serious bugs and opening up more of its products to bug hunters.

GitHub has removed the limit on the maximum amount it will pay researchers for discovering critical bugs and they can now expect to be rewarded between $20,000 and $30,000 for each critical bug.

The company's bug bounty rewards have also been raised at lower levels and high-severity bugs will earn researchers between $10,000 and $20,000, medium-severity rewards will earn them between $4,000 and $10,000 and low-severity rewards are now between $617 to $2,000.

GitHub is also removing some of the legal risks researchers participating in its bug bounty program have been exposed to for violating the site's terms. The company has added a new set of Legal Safe Harbor terms to its site policy.

Researchers will now be protected from violating the terms of the company's site if their actions are carried out specifically for bug bounty research. They will also now be exempt from GitHub's Enterprise Agreement restrictions on reverse engineering and the company vows not to sue them should they overstep the scope of the bug bounty program.

Additionally, all of GitHub's first-party services including GitHub Education, GitHub Leaning Lab, GitHub Jobs and the GitHub Desktop application will be open to researchers searching for bugs.

The company's Phil Turnbull explained why it decided to raise its bug bounty rewards in a blog post, saying:

“We regularly assess our reward amounts against our industry peers. We also recognize that finding higher-severity vulnerabilities in GitHub’s products is becoming increasingly difficult for researchers and they should be rewarded for their efforts. That’s why we’ve increased our reward amounts at all levels.”

Via ZDNet

  • Protect your devices from the latest cyber threats with the best antivirus
Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Pro
cybersecurity
What's the right type of web hosting for me?
Security padlock and circuit board to protect data
Trust in digital services around the world sees a massive drop as security worries continue
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
construction
Building in the digital age: why construction’s future depends on scaling jobsite intelligence
Latest in News
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras