Company news npm security update: Attack campaign using stolen OAuth tokens npm’s impact analysis of the attack campaign using stolen OAuth tokens and additional findings.
Security Seven years of the GitHub Security Bug Bounty program GitHub’s bug bounty program is now a mature component of how we improve product security. We’re excited to highlight some achievements (and interesting vulnerabilities)!
News & insights Four years of the GitHub Security Bug Bounty Last month GitHub celebrated the fourth year of our Security Bug Bounty program. As we’ve done in the past, we’re sharing some details and highlights from 2017 and looking ahead…
Engineering A glimpse into GitHub’s Bug Bounty workflow Last month, we announced the third anniversary of our Bug Bounty Program. While there’s still time to disclose your findings through the program, we wanted to pull back the curtain…