GitHub is restructuring its bug bounty program, shifting incentives away from submission volume and toward reward quality, following months of internal review of the program and broader industry trends in vulnerability disclosure.
A Formal Track for Top Researchers
The company is formalizing a permanent, invite-only VIP program for researchers who consistently deliver high-quality, high-impact findings. Researchers in that tier get higher payouts, faster response times, and closer direct engagement with GitHub's security engineering team. Qualification criteria will be published on GitHub's site, built around demonstrated, consistent quality rather than raw submission counts; the explicit message to researchers is that reward scales with better findings, not more of them.
Static Payouts Replace Ranges
Alongside the new VIP track, GitHub is moving public program payouts to static, single-number rates per severity level instead of wide ranges, arguing that ranges create uncertainty for researchers and overhead internally, while still preserving room for discretionary bonuses on exceptional work. The adjustment is meant to free up more tailored attention and higher rewards for the VIP tier while keeping the public program as an accessible entry point that feeds into it.
A Signal Requirement to Cut Low-Effort Reports
To reduce the volume of low-effort and AI-generated submissions, GitHub is adding a HackerOne signal requirement to its public program. Researchers below the signal threshold get a limited number of initial submissions, up to four, giving genuine newcomers enough room to demonstrate their skills without opening the program to unlimited low-quality noise.
Backlog Protections and What Stays the Same
Reports submitted before the changes take effect will be assessed under the previous structure; the new rules apply to submissions made on or after July 27, 2026. GitHub says its commitment to fast payouts, clear communication, and treating researchers as partners isn't changing, alongside continued investment in faster response times and clearer severity reasoning.
Part of a Broader Security Push
The bounty restructuring follows separate recent GitHub initiatives to assign clear ownership across more than 14,000 repositories and to work down a backlog of over 20,000 secret-scanning alerts across 15,000 repositories, part of a wider effort the company frames as strengthening its overall security posture rather than a single isolated policy change.