Great news. I'm happy to see this program in "public mode" now. GitHub launched this program already as private beta in May 2013.
https://twitter.com/totally_unknown/status/42899282447475916...
Don't expect to earn easy cash here. :)
https://twitter.com/totally_unknown/status/42899282447475916...
Don't expect to earn easy cash here. :)
"We are using a simple severity ranking scheme: Low - Medium - High - Critical. Rewards range from $100 up to $5000 and are determined at our discretion based on a number of factors. For example, if you find a reflected XSS that is only possible in Opera, and Opera is only 1.64% of our traffic, then the severity and reward will be lower. But a persistent XSS that works in Chrome, at 59.53% of our traffic, will earn a much larger reward."