If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: web.archive.org/web/20221205045902/https://github.blog/2021-06-25-seven-years-github-security-bug-bounty-program - Seven years of the GitHub Secu.

site address: web.archive.org/web/20221031235902/https://github.blog/2021-06-25-seven-years-github-security-bug-bounty-program/ redirected to: web.archive.org/web/20221205045902/https://github.blog/2021-06-25-seven-years-github-security-bug-bounty-program

site title: Seven years of the GitHub Security Bug Bounty program The GitHub Blog

Our opinion (on Monday 28 September 2026 1:42:11 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:



Meta tags:
description=GitHub’s bug bounty program is a mature component of our product security. Check out recent milestones (and interesting vulnerabilities)!;
author=;

Headings (most frequently used words):

github, bug, the, bounty, on, from, security, more, codespaces, to, new, how, years, of, program, 2020, insider, private, cybersecurity, spotlight, researcher, universe, 2022, encrypted, columns, seven, highlights, look, ahead, newsletter, related, posts, explore, subscribe, product, platform, support, company, our, favorite, cve, issuance, bounties, ahacker1, eight, yvvdwf, exciting, features, powering, machine, learning, what, with, everything, empowering, developers, helps, teams, ship, secure, software, faster, mitigate, owasp, vulnerabilities, while, staying, in, flow, converts, previously, and, unencrypted, activerecord, readme, project, actions, work, at, universal, open, redirect, pages, visibility, enterprise, server, 22,

Text of the page (most frequently used words):
the (99), github (78), and (60), our (48), bounty (37), security (34), bug (33), this (32), #program (32), for (25), that (17), new (15), more (14), with (14), was (14), private (14), vulnerabilities (13), product (12), from (12), year (12), have (12), how (11), redirect (11), enterprise (10), engineering (10), researchers (10), 2020 (10), products (9), secure (8), you (8), codespaces (8), 2021 (8), team (8), open (8), server (8), vulnerability (8), community (7), can (7), development (7), submissions (7), features (6), code (6), one (6), would (6), com (6), internal (6), other (6), could (6), used (6), user (6), blog (5), about (5), learn (5), out (5), your (5), help (5), users (5), excited (5), some (5), look (5), has (5), programs (5), across (5), also (5), these (5), feature (5), able (5), cve (5), william (5), 2022 (4), developer (4), developers (4), work (4), see (4), what (4), hours (4), highlight (4), researcher (4), years (4), all (4), continued (4), lifecycle (4), interesting (4), process (4), into (4), architecture (4), first (4), were (4), issues (4), when (4), pages (4), risk (4), cves (4), seven (4), details (4), customers (4), submission (4), arguments (4), oauth (4), attacker (4), platform (3), subscribe (3), check (3), everything (3), make (3), post (3), part (3), activerecord (3), upgrades (3), encrypted (3), columns (3), top (3), while (3), flow (3), teams (3), software (3), allows (3), universe (3), month (3), machine (3), another (3), cybersecurity (3), spotlight (3), achievements (3), who (3), june (3), further (3), response (3), additional (3), provide (3), early (3), launched (3), release (3), review (3), access (3), identify (3), site (3), only (3), but (3), capture (3), visibility (3), published (3), public (3), ability (3), through (3), bounties (3), added (3), within (3), request (3), internally (3), any (3), impact (3), url_for (3), method (3), gist (3), location (3), average (3), component (3), organization (2), careers (2), company (2), contact (2), support (2), stories (2), newsletter (2), technical (2), insider (2), actions (2), explore (2), encryption (2), previously (2), unencrypted (2), advanced (2), owasp (2), mitigate (2), putting (2), will (2), ship (2), most (2), free (2), each (2), exciting (2), learning (2), yvvdwf (2), made (2), anniversary (2), forward (2), ahead (2), investment (2), expanding (2), services (2), https (2), created (2), growth (2), refine (2), triage (2), such (2), significant (2), continuing (2), assurance (2), complete (2), unique (2), set (2), validate (2), based (2), add (2), beta (2), step (2), may (2), cross (2), scripting (2), page (2), 000 (2), they (2), identified (2), architectural (2), ensure (2), focused (2), repository (2), create (2), changes (2), design (2), authentication (2), its (2), easily (2), past (2), workflow (2), tooling (2), successful (2), allowed (2), communicate (2), mitre (2), pull (2), fixed (2), issue (2), issuance (2), number (2), cna (2), are (2), allowing (2), additionally (2), participate (2), awarded (2), prevent (2), locations (2), vulnerable (2), controlled (2), after (2), link (2), providing (2), since (2), mitigated (2), however (2), social (2), attacks (2), policy (2), rewards (2), hackerone (2), february (2), highlights (2), seventh (2), continuously (2), now (2), mature (2), search (2), web (2), privacy, terms, inc, linkedin, tiktok, twitch, youtube, facebook, twitter, shop, press, status, training, forum, docs, desktop, electron, atom, partners, api, resources, pricing, customer, covering, techniques, guides, latest, innovations, coming, current, job, openings, native, alongside, hosted, voices, readme, project, data, need, kylie, stradley, second, series, shows, converts, mark, paulsen, address, several, staying, gwen, davis, appsec, expert, niroshan, rajadurai, says, center, enable, meet, goals, empowering, helps, faster, related, posts, thomas, dohmke, building, enhance, integrated, enterprises, drive, innovation, ease, nik, molnar, giving, else, shipped, seth, juarez, discover, enhancements, empower, practitioners, powering, jeff, guerra, contributing, jill, moné, corallo, record, together, eight, logan, maclaren, wrap, awareness, participates, ahacker1, get, best, once, directly, inbox, tags, celebrate, like, extend, thank, participated, broader, throughout, roles, seen, dedicated, execution, participant, expect, faces, side, accelerate, well, expand, initiatives, live, hacking, events, focus, offerings, provides, environment, cloud, which, comes, considerations, bring, designing, implementing, service, way, grateful, participants, currently, engaged, gave, utilize, container, packages, scanning, plus, wanted, extra, included, target, granted, under, two, robert, chen, philip, papurt, handful, combined, rewarded, not, successfully, completing, flag, challenge, fix, before, implement, hardening, offering, resilient, similar, future, bypass, setting, ginkoid, notdeghost, historically, internet, restrict, underlying, great, gives, documentation, sites, portals, required, complex, implemented, complexity, didn, come, without, worked, engineers, implementation, testing, restrictions, pre, addition, earlier, roll, challenging, later, three, far, prove, quickly, advisories, fixes, priority, ready, action, transforms, writeup, json, format, cveproject, cvelist, members, feedback, member, works, supply, description, category, severity, versions, markdown, template, chat, run, off, tracking, formalized, workflows, automation, ties, track, standardized, steps, consistent, clear, discussed, became, authority, being, clearly, consistently, properly, outdated, instances, prioritize, credited, recognize, those, began, issuing, last, appreciate, persistence, dig, order, demonstrate, chained, functionality, read, helper, methods, types, filtering, untrusted, protocols, risky, refactored, use, safe, variants, control, certain, continuous, static, analysis, detect, safeguards, place, type, moved, towards, eliminating, class, whole, codebase, safe_redirect_to, safe_url_for, take, given, prevalence, handlers, utilizing, combination, performs, authenticate, leaked, determined, log, trick, following, their, malicious, found, controllers, supplied, unsafe, ruby, rails, routing, generate, links, javascript, protocol, handler, been, possible, strong, potential, xss, generated, url, choice, fairly, low, facilitate, end, redirecting, directed, content, rare, carry, application, isolation, redirects, typically, useful, stepping, stone, bowling, show, compromise, vakzz, universal, creativity, depth, talent, continues, impress, example, here, closer, received, favorite, chance, thrilled, ongoing, collaboration, better, everyone, skills, interested, participating, scope, rules, visit, website, ranked, paid, days, eligible, report, validated, triaged, partner, times, improved, 2019, 066, 524, 250, 203, brings, overall, moving, 2016, 552, 004, busiest, yet, handled, higher, volume, than, previous, proud, kept, time, reply, payout, aggressive, standards, grown, include, detail, upcoming, invite, ever, growing, core, mission, driving, improvements, develops, key, partnership, 2014, amplified, beyond, achieved, independent, reliable, improves, greg, ose, author, improve, keyword, sales, trial, education, changelog, source, wayback, http, archive, org, 20221205045902, timestamps, fail, success, 2023, jan, dec, nov, jun, 2026, captures,


Text of the page (random words):
seven years of the github security bug bounty program the github blog 67 captures 25 jun 2021 11 may 2026 nov dec jan 05 2021 2022 2023 success fail about this capture timestamps the wayback machine http web archive org web 20221205045902 https github blog 2021 06 25 seven years github security bug bounty program blog engineering product security open source enterprise changelog community education company policy free trial contact sales search by keyword search security seven years of the github security bug bounty program github s bug bounty program is now a mature component of how we improve product security we re excited to highlight some achievements and interesting vulnerabilities author greg ose june 25 2021 security is core to github s mission and our product security engineering team is focused on continuously driving improvements to how github develops secure software one key component of github s security development lifecycle is our partnership with security researchers and the bug bounty community through the github security bug bounty program launched in 2014 this program and our researchers have amplified our ability to ship secure products beyond what we could have achieved as an independent team at github now in its seventh year github s bug bounty program is a mature and reliable component of how github continuously improves the security of our products in this post we re excited to highlight the achievements of the seventh year of our bug bounty program detail some interesting vulnerabilities we ve mitigated through the program look forward to the upcoming year and invite the community to participate in our ever growing bounty program 2020 highlights 2020 was our busiest year yet from february 2020 to february 2021 we handled a higher volume of submissions than any previous year we re proud that we ve kept our time to first reply triage and payout for submissions within our aggressive standards as the program has grown some highlights from the past year include 524 250 in bounties awarded for 203 vulnerabilities in our products and services this brings the overall rewards from our program since moving to hackerone in 2016 to 1 552 004 1 066 submissions across our public and private programs our response times improved by 4 hours from 2019 to an average of 13 hours to first response submissions were validated and triaged internally to partner teams within 24 hours on average bounties were paid out on average 24 days after the submission of an eligible report our program was ranked as one of the top programs on hackerone each submission to our bug bounty program is a chance to make github our products the developer community and our customers more secure and we re thrilled with the ongoing collaboration to make github better for everyone with the help of your skills if you re interested in participating visit our website for details of the program s scope rules and rewards our favorite bug from 2020 the creativity and depth of technical talent that we see in submissions to our bounty program continues to impress us as an example here s a closer look at one of the most interesting submissions we received in 2020 universal open redirect it s rare to see an open redirect vulnerability carry significant impact or risk to an application in isolation open redirects are typically only useful as a stepping stone for social engineering attacks however william bowling vakzz was able to show how an open redirect vulnerability on github com could be used to compromise the oauth flow of gist users william found that a method used across a number of controllers on github com supplied unsafe and user controlled arguments to ruby on rails url_for routing method to generate links and redirect locations by providing a javascript protocol handler cross site scripting would have been possible but since github com has a strong content security policy the risk of potential xss was mitigated however this generated url was used as a redirect location and it could be used to redirect users to a location of an attacker s choice while the risk is fairly low this vulnerability could be used to facilitate social engineering attacks by providing a link to github com that would end up redirecting to an attacker directed site william was able to take the impact of this bug one step further given the prevalence of the vulnerable method across our request handlers by utilizing this redirect in combination with the oauth flow that github com performs to authenticate to github gist he was able to redirect the user after a successful oauth authentication so that the user s oauth code would be leaked to a location determined by the attacker this would have allowed the attacker to log into github gist for any user they could trick into following their malicious link internally at github we have helper methods safe_url_for and safe_redirect_to to prevent these types of vulnerabilities by filtering out untrusted redirect locations protocols and other risky arguments to mitigate the open redirect vulnerability we refactored the vulnerable code to use these safe variants and prevent the user control of certain arguments to url_for additionally we added a check to our continuous static analysis tooling to detect when url_for is added to new code with user controlled arguments by putting these safeguards in place to capture this type of vulnerability we moved towards eliminating this class of vulnerabilities as a whole across our codebase we awarded 10 000 for this submission and we appreciate william s persistence in continuing to dig in order to demonstrate the impact an open redirect can have when chained with other functionality you can read more about this vulnerability on william s blog cve issuance as discussed in last year s bug bounty anniversary post in 2020 github became a cve number authority cna with mitre and we began issuing cves for vulnerabilities in github enterprise server being a cna allows us to clearly and consistently communicate to customers the issues that are fixed in our products allowing customers to properly identify outdated github enterprise server instances and prioritize upgrades additionally any vulnerability we issue for github enterprise server from a bug bounty submission is credited to the researcher in the cve allowing us to further recognize those researchers that participate in our program to support this process we formalized our internal workflows for cve issuance we created automation that ties into how we track vulnerabilities internally as github issues and standardized the steps to ensure consistent and clear details in our cves a chat op is run to create a new pull request based off of an internal vulnerability tracking issue we have for all product vulnerabilities at github a member of the product security engineering team works to supply all of the details such as a description category severity and fixed versions in a markdown template other members of product security engineering and engineering teams review this and provide feedback within the pull request when it s ready to be published a github action transforms this writeup to the json format used by mitre so that it can be added to the cveproject cvelist repository in the past year we have continued to refine this workflow and tooling and have published three cves for github enterprise server so far in 2021 this workflow has continued to prove successful and has allowed us to quickly complete the cve process for seven additional advisories the more cves and details we can provide on fixes to our products the more easily we can communicate the priority of upgrades to our github enterprise server customers private bug bounties in 2020 we continued our work on private bug bounty programs for beta and other pre release products in addition to our public bounty program private bounty programs help us identify issues earlier in the software development lifecycle for new products and features so that we can more easily roll out architecture and design changes that would be challenging later in development github pages private visibility one private bug bounty program in 2020 focused on visibility restrictions for github pages historically when a github page was published it was made public to the internet with this new feature users have the ability to restrict access to only github users who have access to the underlying repository this is a great feature that gives you the ability to create internal documentation sites or portals but it also required complex architectural changes to how github pages was implemented this complexity didn t come without risk and the product security engineering team worked with our engineers to design the authentication process for github pages and validate its implementation through internal security testing and code review for additional assurance we also included this feature as a target for a private bug bounty program we granted our private bug bounty researchers early access to the feature while it was under development in may 2020 two researchers robert chen notdeghost and philip papurt ginkoid were able to identify cross site scripting and a handful of other vulnerabilities that could be combined to bypass the visibility setting on a github page we rewarded these researchers 35 000 not only for the vulnerabilities they identified but also for successfully completing the capture the flag challenge we set up as part of the bounty we were able to fix the identified issues before this feature launched and also implement architectural hardening to ensure this offering is more resilient to similar vulnerabilities in the future github enterprise server 2 22 in 2020 we also gave our private bug bounty researchers an early look at github enterprise server 2 22 this was the first github enterprise server release to utilize a new container based architecture and was the first release to add github actions packages and github advanced security code scanning as beta features with all of these new features plus a new architecture we wanted to add this extra step of review to our security development lifecycle codespaces this year we re continuing to focus on expanding our private program to provide early assurance of new features and product offerings in june we launched a new private bounty for codespaces codespaces provides a complete development environment in the cloud which comes with a unique architecture and a unique set of security considerations the private bug bounty allows us to bring in researchers to help us validate our internal work designing and implementing this service in a secure way we re grateful to the participants currently engaged in this private program a look ahead 2021 has seen significant investment and growth across github s security program in june we created a new internal team dedicated to the execution and growth of our bug bounty program if you re a participant in our program expect to see some new faces on the other side of your submissions this team will help further accelerate and refine our triage and response process as well as expand into new initiatives such as live hacking events and additional private bug bounty programs as we celebrate the anniversary of the bug bounty program we would like to extend another thank you to all the researchers who have participated in the program we look forward to the year ahead as part of our continued investment in github s security we re expanding the product security engineering team and the broader github security organization if the work we do in our bug bounty program and throughout our development lifecycle to secure our products and services is interesting to you check out our open roles at https github com about careers tags bug bounty codespaces the github insider newsletter get the best of github once a month directly to your inbox subscribe more on bug bounty cybersecurity spotlight on bug bounty researcher ahacker1 as we wrap up cybersecurity awareness month the github bug bounty team is excited to spotlight one of the security researchers who participates in the github security bug bounty program logan maclaren eight years of the github security bug bounty program it was another record year for our security bug bounty program we re excited to highlight some achievements we ve made together with the bounty community from 2021 jill moné corallo cybersecurity spotlight on bug bounty researcher yvvdwf we re excited to highlight another top contributing researcher to github s bug bounty program yvvdwf jeff guerra more on codespaces exciting new github features powering machine learning discover the exciting enhancements in github that empower machine learning practitioners to do more seth juarez what s new with codespaces from github universe 2022 we re giving github users 60 free hours each month on codespaces learn what else we shipped for codespaces at universe this year nik molnar everything new from github universe 2022 see what we re building to enhance the most integrated developer platform that allows developers and enterprises to drive innovation with ease thomas dohmke related posts product how empowering developers helps teams ship secure software faster appsec expert niroshan rajadurai says putting developers at the center of everything will enable you to meet your security goals gwen davis security how to mitigate owasp vulnerabilities while staying in the flow explore how github advanced security can help address several of the owasp top 10 vulnerabilities mark paulsen engineering how github converts previously encrypted and unencrypted columns to activerecord encrypted columns this post is the second part in a series about activerecord encryption that shows how github upgrades previously encrypted and unencrypted columns to activerecord encryption kylie stradley explore more from github security secure platform secure data everything you need to make security your 1 learn more the readme project stories and voices from the developer community learn more github actions native ci cd alongside code hosted in github learn more work at github check out our current job openings learn more subscribe to the github insider a newsletter for developers covering techniques technical guides and the latest product innovations coming from github subscribe product features security enterprise customer stories pricing resources platform developer api partners atom electron github desktop support docs community forum training status contact company about blog careers press shop github on twitter github on facebook github on youtube github on twitch github on tiktok github on linkedin github s organization on github 2022 github inc terms privacy
Thumbnail images (randomly selected): * Images may be subject to copyright.GREEN status (no comments)
  • loading
  • Greg Ose
  • Security
  • The ReadME Project
  • GitHub Actions
  • Work at GitHub!

Verified site has: 84 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-55 56-60 61-65 66-70 71-75 76-80 81-84


The site also has references to the 2 subdomain(s)

  archive.org  Verify   help.archive.org  Verify


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/1.1 302 FOUND
Server nginx
Date Mon, 28 Sep 2026 01:42:11 GMT
Content-Type text/plain; charset=utf-8
Content-Length 0
Connection close
x-archive-redirect-reason found capture at 20221205045902
location htt???/web.archive.org/web/20221205045902/htt????/github.blog/2021-06-25-seven-years-github-security-bug-bounty-program/
server-timing captures_list;dur=0.356713, exclusion.robots;dur=0.035601, exclusion.robots.policy;dur=0.028629, esindex;dur=0.006536, cdx.remote;dur=14.731657, LoadShardBlock;dur=212.929473, PetaboxLoader3.resolve;dur=57.544014, PetaboxLoader3.datanode;dur=148.673885
x-app-server wwwb-app204-dc6
x-ts 302
x-tr 242
server-timing TR;dur=0,Tw;dur=0,Tc;dur=0
set-cookie wb-p-SERVER=wwwb-app204; path=/
X-location All
X-AS 16276
X-RL 0
X-NA 0
X-Page-Cache MISS
Server-Timing MISS
X-NID OVH SAS
Referrer-Policy no-referrer-when-downgrade
Permissions-Policy interest-cohort=()
X-sd 0
HTTP/1.1 200 OK
Server nginx
Date Mon, 28 Sep 2026 01:42:11 GMT
Content-Type text/html; charset=UTF-8
Transfer-Encoding chunked
Connection close
x-archive-orig-server nginx
x-archive-orig-date Mon, 05 Dec 2022 04:59:02 GMT
x-archive-orig-x-crawler-transfer-encoding chunked
x-archive-orig-connection keep-alive
x-archive-orig-x-hacker If you re reading this, you should visit wpvip.com/careers and apply to join the fun, mention this header.
x-archive-orig-x-powered-by WordPress VIP <htt????/wpvip.com>
x-archive-orig-host-header a9130478a60e5f9135f765b23f26593b
x-archive-orig-link <htt????/github.blog/wp-json/>; rel= htt????/api.w.org/
x-archive-orig-link <htt????/github.blog/wp-json/wp/v2/posts/58818>; rel= alternate ; type= application/json
x-archive-orig-link <htt????/wp.me/pamS32-fiG>; rel=shortlink
x-archive-orig-x-rq dca6 0 4 9980
x-archive-orig-cache-control max-age=300, must-revalidate
x-archive-orig-x-crawler-content-encoding gzip
x-archive-orig-age 0
x-archive-orig-x-cache miss
x-archive-orig-vary Accept-Encoding
x-archive-orig-accept-ranges bytes
x-archive-orig-strict-transport-security max-age=31536000;includeSubdomains;preload
x-archive-orig-content-length 94528
x-archive-guessed-content-type text/html
x-archive-guessed-charset utf-8
memento-datetime Mon, 05 Dec 2022 04:59:02 GMT
link <htt????/github.blog/2021-06-25-seven-years-github-security-bug-bounty-program/>; rel= original , <htt???/web.archive.org/web/timemap/link/htt????/github.blog/2021-06-25-seven-years-github-security-bug-bounty-program/>; rel= timemap ; type= application/link-format , <htt???/web.archive.org/web/htt????/github.blog/2021-06-25-seven-years-github-security-bug-bounty-program/>; rel= timegate , <htt???/web.archive.org/web/20210625160409/htt????/github.blog/2021-06-25-seven-years-github-security-bug-bounty-program/>; rel= first memento ; datetime= Fri, 25 Jun 2021 16:04:09 GMT , <htt???/web.archive.org/web/20220924230124/htt????/github.blog/2021-06-25-seven-years-github-security-bug-bounty-program/>; rel= prev memento ; datetime= Sat, 24 Sep 2022 23:01:24 GMT , <htt???/web.archive.org/web/20221205045902/htt????/github.blog/2021-06-25-seven-years-github-security-bug-bounty-program/>; rel= memento ; datetime= Mon, 05 Dec 2022 04:59:02 GMT , <htt???/web.archive.org/web/20221205142716/htt????/github.blog/2021-06-25-seven-years-github-security-bug-bounty-program/>; rel= next memento ; datetime= Mon, 05 Dec 2022 14:27:16 GMT , <htt???/web.archive.org/web/20260511142505/htt????/github.blog/2021-06-25-seven-years-github-security-bug-bounty-program/>; rel= last memento ; datetime= Mon, 11 May 2026 14:25:05 GMT
content-security-policy default-src self unsafe-eval unsafe-inline data: blob: archive.org web.archive.org web-static.archive.org wayback-api.archive.org athena.archive.org analytics.archive.org pragma.archivelab.org wwwb-events.archive.org
x-archive-src CC-MAIN-2022-49-1669446711003.56-0039/CC-MAIN-20221205032447-20221205062447-00793.warc.gz
server-timing captures_list;dur=0.751726, exclusion.robots;dur=0.068723, exclusion.robots.policy;dur=0.054397, esindex;dur=0.010263, cdx.remote;dur=24.843573, LoadShardBlock;dur=121.004566, PetaboxLoader3.datanode;dur=56.181660, PetaboxLoader3.resolve;dur=80.706314, load_resource;dur=92.503850, nav;dur=0.324339
x-app-server wwwb-app247-dc8
x-ts 200
x-tr 466
server-timing TR;dur=0,Tw;dur=0,Tc;dur=1
set-cookie wb-p-SERVER=wwwb-app247; path=/
X-location All
X-AS 16276
X-RL 0
X-NA 0
X-Page-Cache MISS
Server-Timing MISS
X-NID OVH SAS
Referrer-Policy no-referrer-when-downgrade
Permissions-Policy interest-cohort=()
X-sd 0
Content-Encoding gzip

Meta Tags

title="Seven years of the GitHub Security Bug Bounty program | The GitHub Blog"
charset="UTF-8"
name="viewport" content="width=device-width, initial-scale=1"
name="robots" content="index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1"
name="description" content="GitHub’s bug bounty program is a mature component of our product security. Check out recent milestones (and interesting vulnerabilities)!"
property="og:locale" content="en_US"
property="og:type" content="article"
property="og:title" content="Seven years of the GitHub Security Bug Bounty program | The GitHub Blog"
property="og:description" content="GitHub’s bug bounty program is a mature component of our product security. Check out recent milestones (and interesting vulnerabilities)!"
property="og:url" content="htt???/web.archive.org/web/20221205045902/htt????/github.blog/2021-06-25-seven-years-github-security-bug-bounty-program/"
property="og:site_name" content="The GitHub Blog"
property="article:publisher" content="htt????/www.facebook.com/GitHub"
property="article:published_time" content="2021-06-25T16:01:03+00:00"
property="article:modified_time" content="2021-08-11T01:06:59+00:00"
property="og:image" content="htt???/web.archive.org/web/20221205045902im_/htt????/github.blog/wp-content/uploads/2021/06/GitHub-Bug-Bounty_for-social.png?fit=1200%2C630"
property="og:image:width" content="1200"
property="og:image:height" content="630"
property="og:image:type" content="image/png"
name="author" content="Greg Ose"
name="twitter:card" content="summary_large_image"
name="twitter:image" content="htt???/web.archive.org/web/20221205045902im_/htt????/github.blog/wp-content/uploads/2021/06/GitHub-Bug-Bounty_for-social.png?fit=1200%2C630"
name="twitter:creator" content="@github"
name="twitter:site" content="@github"
name="twitter:label1" content="Written by"
name="twitter:data1" content="Greg Ose"
name="twitter:label2" content="Est. reading time"
name="twitter:data2" content="9 minutes"
name="generator" content="WordPress 6.1.1"
name="parsely-title" content="Seven years of the GitHub Security Bug Bounty program"
name="parsely-link" content="htt???/github.blog/2021-06-25-seven-years-github-security-bug-bounty-program/"
name="parsely-type" content="post"
name="parsely-image-url" content="htt????/github.blog/wp-content/uploads/2019/09/security-1200-630.png?resize=150%2C150"
name="parsely-pub-date" content="2021-06-25T16:01:03Z"
name="parsely-section" content="Security"
name="parsely-tags" content="bug bounty,codespaces"
name="parsely-author" content="Greg Ose"
name="ha-url" content="htt????/collector.githubapp.com/github-blog/collect"
name="msapplication-TileImage" content="htt????/github.blog/wp-content/uploads/2019/01/cropped-github-favicon-512.png?fit=270%2C270"

Load Info

page size29299
load time (s)1.613929
redirect count1
speed download18164
server IP 207.241.237.3
* all occurrences of the string "http://" have been changed to "htt???/"