preloader

· devops digital-security github supply-chain developer-tools europe vulnerability-management

GitHub Is Halving Public Bug Bounty Payouts. If You Rely on Outside Researchers Finding Your Flaws, That Should Worry You

Source: GitHub Security Blog / The Hacker News / InfoWorld

GitHub announced a restructuring of its bug bounty program that takes effect on 27 July, and the headline number is a straightforward cut. Public payouts are dropping by roughly half across every severity tier: critical findings fall from a previous range of $20,000 to $30,000-plus down to a fixed $10,000, with medium, high and low-severity rewards reduced by comparable margins. The largest payments, $30,000 and up, now sit behind a new permanent, invite-only VIP tier reserved for a smaller pool of established researchers.

Reports filed before the deadline keep the old rate

Anyone with a report already sitting in GitHub’s triage queue, or filed before 27 July, keeps the previous payout terms, so the change is not retroactive. GitHub frames the restructuring as a way to reduce noise in its submission pipeline and give the researchers it already trusts faster responses and closer access to its security engineering team, building on a policy change from May 2026 that started requiring working proofs of concept and demonstrated impact before a report would even be considered.

Fewer independent eyes on infrastructure millions of teams depend on

Whatever the internal reasoning, the practical effect of halving public rewards is a weaker financial incentive for independent researchers to spend time hunting for flaws in GitHub’s platform, one of the most heavily relied-upon pieces of developer infrastructure in the world, including for source code, CI/CD pipelines and secrets across a huge share of European engineering organisations. Bug bounty programs exist because internal security teams cannot realistically find everything themselves. When the public program pays less, some of that outside scrutiny does not disappear entirely, but it does shift toward whichever platform still pays competitively, and the gap left behind is filled by nobody unless an organisation compensates with more of its own testing.

What this means for your own environment

If your organisation’s security posture leans on the assumption that widely used platforms like GitHub are being continuously and thoroughly tested by the wider research community, this is a signal to check that assumption rather than take it on faith. That applies doubly to any internal tooling, self-hosted Git infrastructure or CI/CD pipelines that never had public bug bounty coverage in the first place and rely entirely on whatever testing your own team has time for.

If you want an independent security review of your development pipeline, from source control through CI/CD to deployment, rather than hoping someone else finds the problems first, contact Excello Digital. We help European engineering teams build the internal testing and review discipline that outside bounty programs were never a substitute for.

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!