Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Just because a bounty policy isn't disclosed doesn't mean it doesn't exist.


I've reported several vulnerabilities to GitHub. There is no bounty policy.


yeah +1. @joernchen also did I remember. And lots of other people.

Hey, anyone, is github that super profitable company with 100mln investments ? They got no money or what?


I guess people disclose enough vulns voluntarily that they don't need to offer a bounty as an incentive.


= cheating


trust me, it doesn't exist.


I got a t-shirt some time back for reporting a serious XSS vulnerability.


they like you.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: