GitHub、バグ報奨金プログラムを再構築
GitHub はセキュリティ研究コミュニティの質を重視し、VIP プログラムの導入とバウンティ報酬体系の構造的変更を発表した。
キーポイント
永久 VIP プログラムの創設
高品質かつ高インパクトな成果を一貫して提供する研究者を対象に、招待制の VIP プログラムを正式化し、より高い報酬と迅速な対応を提供する。
報酬体系の静的化と引き上げ
バウンティ報酬を範囲から固定金額へ変更し、研究者側の不確実性を排除すると同時に、重大度ごとの報酬額を引き上げて質の高い報告をインセンティブ化する。
質への転換とノイズ削減
提出数の増加によるキューの混雑に対処するため、「より多く提出する」のではなく「より良く提出する」ことを評価基準とし、信号(重要な脆弱性)に集中する方針を明確化した。
VIP 資格取得の明確化
HackerOne ページ上で公開される明確な基準に基づき、特定の重大度の発見数や質を満たすことで VIP プログラムへの昇格が可能となるパスを提示した。
低品質レポートの削減と新規研究者への対応
AI生成や低effortな報告を減らすため、HackerOneのシグナル閾値を満たさない研究者には提出数制限(最大4件)を設けるが、これは新規参入者への障壁ではなく、実力証明のための猶予期間である。
既存報告の保護と新ルールの適用日
2026年7月27日以降に提出されたレポートのみが新しい報酬構造で評価され、それ以前の報告は旧ルールに基づいて処理される。
研究者との関係構築とプログラムの進化
報酬体系の改変に加え、応答速度の向上やコンファレンスでの対話などを通じて、信頼関係を築きつつ深い研究を奨励するプログラムへと進化させる。
重要な引用
The core shift here is in what we're incentivizing: you don't earn more by submitting more. You earn more by submitting better.
These decisions comes after months of reflecting on our program, analyzing what's happening across the industry, and thinking about researcher experience.
Ranges sound flexible, but in practice they create uncertainty for researchers and overhead for our team.
This isn't a wall against new researchers. HackerOne's platform gives researchers who don't meet the threshold up to four initial submissions, which is enough runway for a newcomer with a genuine finding to demonstrate their skills.
The security research community is one of GitHub's greatest assets.
影響分析・編集コメントを表示
影響分析
この変更は、セキュリティ研究者に対して単なる報告数の増加ではなく、深い調査と高品質な成果を追求するよう促す強力なインセンティブとなり、GitHub のセキュリティ体制の強化に寄与します。また、報酬体系の透明化と VIP プログラムの制度化により、優秀なリサーチャーとの長期的なパートナーシップ構築が加速し、業界全体のバウンティプログラムの質的向上へのモデルケースとなる可能性があります。
編集コメント
GitHub がバウンティプログラムの見直しに踏み切った背景には、報告数の増加に伴う処理負荷の増大と、質の高いリサーチャーとの関係深化への課題意識があると推察されます。固定報酬と VIP 制度の導入は、研究者側の予測可能性を高めつつ、企業側も重要な脆弱性への対応リソースを最適化できる合理的な施策と言えます。
セキュリティ研究コミュニティは、GitHub をすべての人にとってより安全な場所にしています。これがバグ報奨金プログラムを運営するシンプルな理念です。
過去 10 年以上にわたり、世界中の研究者が脆弱性を悪用される前に発見・修正する手助けをしてくれました。私たちは、彼らの時間を無駄にしないようなプログラムになるよう努めてきました。
今日、プログラムの運用方法について重要な変更を発表します。これらの決定は、数か月にわたる自社のプログラムへの振り返り、業界全体の動向分析、そして研究者の体験向上に向けた検討を経て導き出されたものです。
何が変わり、なぜなのか
プログラムには処理待ちの案件が急増しています。新規参入する研究者の増加や、既存の協力者たちの活動加速に対応するため、すでに調整を実施しました。これらの変更点は、直近のブログ記事で共有済みです。
今回の変更は主に 2 つの目的に基づいています。一つはノイズを減らし、重要な報告に集中できる体制を整えること。もう一つは、真面目な研究者にとって参加価値のあるプログラムへと進化させることです。
恒久 VIP プログラムの導入
高品質でインパクトの大きい成果を継続的に提供する資格を持つ研究者向けに、恒久的な非公開(招待制)VIP プログラムを正式に開始します。VIP に認定された研究者には、報奨金の増額、応答時間の短縮、セキュリティエンジニアチームとの緊密な連携が提供されます。
この取り組みの目的は、GitHub の仕組みを深く理解するために多大な努力を払った研究者が、私たちと直接協働できる場を作ることです。彼らの貢献に見合った体験を提供し、その努力を正当に評価する環境を整えることが狙いです。
VIP プログラムの報奨金テーブル
深刻度別報奨金
低:1,000 ドル
中:7,500 ドル
高:20,000 ドル
重大:30,000 ドル以上
対象となる条件:
明確な基準は、公開されている HackerOne のページで発表します。参加への道筋は、「実証された一貫した質」を軸に構築されています。以下のいずれかを達成することで資格を得られます。
- 重大な脆弱性報告が 1 つ
- 高い深刻度の報告が 2 つ
- 中程度の報告が 4 つ
- 低い深刻度の報告が 7 つ
今回の大きな転換点は、報奨金のインセンティブ設計にあります。提出数で報酬が増えるのではなく、「より質の高い報告」を出すことで報酬が上がります。
再編された公開プログラムにおける報奨金テーブル
上記の優先順位変更を確実に実行するためには、それを可能にする仕組みの変更も必要です。私たちは、報告数の多さよりも「関係の質」と「発見の質」に焦点を移す方針に合わせて、公開プログラムの報酬率を見直します。また、今後は幅広な範囲ではなく、深刻度レベルごとに単一の明確な金額とする「固定報奨金」へ移行します。
範囲を示すと柔軟に見えるかもしれませんが、実際には研究者にとって不確実性を生み、チーム側には事務負担を増やす要因となります。一方、固定報奨金は双方に明確な期待値を設定し、さらに優れた成果に対しては裁量による追加ボーナスを支払う柔軟性も維持できます。
新しい公開プログラムの報奨金テーブル:
低:250 ドル
中:2,000 ドル
高:5,000 ドル
重大:10,000 ドル
この見直しにより、VIP プログラムに対してより手厚い対応と高い報酬を提供できるようになります。同時に、公開プログラムは引き続き探索の場として機能し、VIP プログラムへの登竜門としての役割も果たします。
シグナル要件の強化
低品質や AI が生成した報告書の数を減らすため、公開プログラムにおいて HackerOne のシグナル要件を導入します。まだシグナル基準を満たしていない研究者には、実績を築くまでの間、提出できる件数に制限を設けます。
これは新規研究者に対する壁を作るものではありません。HackerOne のプラットフォームでは、基準を満たさない研究者にも最大 4 件の初期提出枠が用意されており、真の脆弱性を見つけた新人がその能力を示すには十分な余地があります。私たちはセキュリティ研究コミュニティ全体へのアクセス性を保ちたいと考えています。ただ、プログラムをすべての関係者にとって運用可能なものにするための最低限の基準が必要なのです。
変わらないこと
実際のセキュリティ研究に対する報酬というコミットメントは変わりません。迅速な支払い、明確なコミュニケーション、そして研究者をパートナーとして扱う姿勢は継続されます。
今回の変更発効前に提出された報告書については、以前のバウンティ構造に基づいて対応します。過去の未処理分も適用範囲外とし、新しい評価基準が適用されるのは 2026 年 7 月 27 日以降に提出された報告書のみとなります。
今後の展望
これは、私たちが取り組んでいるより広範な進化の一部です。バウンティの再編成や VIP プログラムと並行して、私たちは応答時間の短縮、深刻度の判断理由の明確化、そしてコミュニティとの関わりを深めることに投資しています。優れた協力関係は、単なる報酬表だけで築かれるものではありません。DEF CON などのカンファレンスで直接私たちと交流することも可能ですし、継続的なアウトリーチを通じて私たちの声を聞くこともできます。私たちはセキュリティカンファレンスでの研究者コミュニティとの出会いを楽しみにしており、関係を構築しながら、私たちが最も重視する深みのある思索的な研究を報奨するバウンティプログラムのあり方をさらに探求していきたいと考えています。
セキュリティリサーチコミュニティは、GitHub にとって最大の資産の一つです。今回の変更は、このコミュニティへの敬意を表すためのものです。私たちは、価値ある研究を引き寄せ、この仕事に対する私たちの真剣さを反映した体験を提供し、研究者がレポートを提出するたびに寄せてくれる信頼に応えるプログラムを構築したいと考えています。
またどこかでお会いしましょう。ハッキングを楽しんでください!
本記事「Next chapter: Restructuring GitHub’s bug bounty program」は、The GitHub Blog に掲載されました。
原文を表示
The security research community makes GitHub safer for everyone. That’s the simple idea behind our bug bounty program.
For more than a decade, researchers from around the world have helped us find and fix vulnerabilities before they could be exploited, and we’ve worked hard to be a program worth their time.
Today, we’re sharing some meaningful changes to how the program works. These decisions comes after months of reflecting on our program, analyzing what’s happening across the industry, and thinking about researcher experience.
What’s changed and why
The program is facing an increasing queue. We have already made adjustments to accommodate the rise in new researchers and the acceleration in efforts of researchers we’ve been working with. We shared these changes in a recent blog post.
These changes are about two things: reducing the noise so we can focus on the signal, and building a program that serious researchers find rewarding to participate in.
Introducing a permanent VIP program
We’re formalizing a permanent private/invite-only VIP program for qualified researchers who consistently deliver high-quality, high-impact work. VIP researchers get higher payouts, faster response times, and a closer working relationship with our security engineering team. The goal is to create a space where the researchers who invest deeply in understanding GitHub can work with us directly and get an experience that reflects the effort they put in.
VIP program bounty table:
Severity Payout
Low $1,000
Medium $7,500
High $20,000
Critical $30,000+
How to qualify: We’ll publish clear criteria on our public HackerOne page. The path in is built around demonstrated, consistent quality. To qualify, you must accomplish at least one of the following:
One critical finding
Two high findings
Four medium findings
Seven low findings
The core shift here is in what we’re incentivizing: you don’t earn more by submitting more. You earn more by submitting better.
A restructured public bounty table
To commit ourselves to the changes in our prioritization above, we also must make changes that enable it. We are adjusting our public program rates to accommodate this shift in focus towards quality of relationships and findings over quantity of reports. We are also updating to static payouts—a single, clear number per severity level, rather than a wide range. Ranges sound flexible, but in practice they create uncertainty for researchers and overhead for our team. Static payouts set clear expectations on both sides, and we retain the ability to award discretionary bonuses for work that goes above and beyond.
Our new public program bounty table:
Severity Payout
Low $250
Medium $2,000
High $5,000
Critical $10,000
This adjustment will enable us to provide more tailored attention and higher rewards to our VIP program, while still enabling our public program to be a place to explore and serve as a feeder into the VIP program.
Raising the signal requirement
To reduce the volume of low-effort and AI-generated reports, we’re implementing a HackerOne signal requirement on the public program. Researchers who don’t yet meet the signal threshold will have a limited number of allowed submissions while they establish a track record.
This isn’t a wall against new researchers. HackerOne’s platform gives researchers who don’t meet the threshold up to four initial submissions, which is enough runway for a newcomer with a genuine finding to demonstrate their skills. We want to remain accessible to the full security research community; we just need a baseline that keeps the program workable for everyone.
What stays the same
Our commitment to rewarding real security research isn’t changing. We’ll continue to pay out quickly, communicate clearly, and treat researchers as the partners they are.
Reports submitted before these changes take effect will be honored under the previous bounty structure. We’re grandfathering the backlog so that only reports made on or after July 27, 2026 will be assessed with the new structure.
Looking ahead
This is one part of the broader evolution we’re working through. Alongside the bounty restructuring and the VIP program, we’re investing in faster response times, clearer severity reasoning, and more community engagement. Great working relationships are built on more than a pay table. You can engage directly with us at conferences like DEFCON and you’ll hear from us through ongoing outreach. We look forward to joining the researcher community at security conferences, building relationships, and continuing to explore ways to make our bug bounty program one that rewards the kind of deep, thoughtful research we care about most.
The security research community is one of GitHub’s greatest assets. These changes are meant to honor them. We want to build a program that attracts the research we value, creates an experience that reflects how seriously we take this work, and upholds the trust researchers place in us every time they submit a report.
We’ll see you out there, and happy hacking!
The post Next chapter: Restructuring GitHub’s bug bounty program appeared first on The GitHub Blog.
関連記事
今日のまとめ
AI日報で今日の重要ニュースをまとめ読み