Dispatch
GitHub restructures its bug bounty program around researcher experience
GitHub announced significant changes to its bug bounty program, refocusing on the researcher experience of working with the security team rather than payout mechanics alone. Coming from the platform hosting most of the world's source code — and increasingly the agent harnesses acting on it — the scope and triage changes matter to anyone reporting supply-chain issues. Pairs directly with the PyPI upload restriction as a package-ecosystem hardening trend.
Source
↳ Follow the thread