oss-bounty-program
嗯,用户让我用中文总结一篇文章,控制在100字以内,而且不需要特定的开头。我得先仔细阅读这篇文章,理解它的主要内容。 文章是关于ProjectDiscovery的开源安全漏洞赏金计划。看起来他们希望通过奖励全球社区的贡献来民主化安全。目标包括降低参与门槛、激励高质量贡献、促进透明公平的社区,以及改善整体安全生态系统。 接下来,文章详细说明了适用的项目范围、参与条件、合格贡献类型、奖励结构以及如何参与。还有关于审查评估、安全披露、支付法律条款和行为准则的内容。 用户要求总结在100字以内,所以我要抓住核心要点:计划的目的、涵盖的项目、激励措施以及对社区的影响。确保语言简洁明了,不使用任何复杂的术语。 最后,检查一下字数是否符合要求,并确保没有遗漏关键信息。这样用户就能快速了解文章的主要内容了。 </think> ProjectDiscovery推出开源安全漏洞赏金计划,旨在通过奖励全球社区贡献 democratize security。该计划覆盖多个开源项目,激励高质量代码改进和安全修复,并提供透明公平的奖励机制,推动开放源代码安全工具发展。 2026-1-9 12:3:24 Author: github.com(查看原文) 阅读量:7 收藏

The ProjectDiscovery OSS Bounty Program exists to democratize security by rewarding meaningful contributions from the global community.

Our tools are used by researchers, defenders, and builders worldwide. This program ensures that anyone, anywhere, can contribute to improving ProjectDiscovery projects and be fairly recognized or rewarded for their work.

We aim to:

  • Lower the barrier to participation in security research and development
  • Incentivize high-impact open-source contributions
  • Foster a transparent, fair, and collabrative community
  • Improve the security ecosystem for everyone

In-Scope Projects

  • The program applies to official ProjectDiscovery open-source repositories, including but not limited to:
    • Nuclei
    • Katana
    • Subfinder
    • Httpx
    • Naabu
    • ShuffleDNS
    • DNSx
    • TLSx
    • Vulnx
    • URLFinder
    • any other repositories explicitly labeled as bounty.
  • Projects must be publicly available
  • Issues or tasks eligibile for bounties will be clearly labeled (e.g., bounty)

Out-of-Scope Projects

  • Third-party dependencies
  • Forks or unofficial repositories

Who Can Participate

  • Anyone worldwide may participate
  • Contributors must be legally able to receive rewards
  • ProjectDiscovery employees and core maintainers may contribute but are not eligible for monetary rewards

The program is open, inclusive, and global.

Eligible Contributions

Only work explicitly marked or approved qualifies.

Eligible:

  • Bug fixes for confirmed issues
  • Performance improvements
  • Feature implementations (request by maintainers)
  • Documentation or testing improvements with meaningful impact
  • Tooling & infrastructure enhancements

Not Eligible:

  • Unapproved or unsolicited features
  • Duplicate submissions
  • Trivial or low-quality changes
  • Known or already-reported security issues
  • Any unethical, fraudulent, or abusive behavior

Reward Structure

Monetary Bounties

  • Fixed or variable rewards depending on impact
  • Amounts are disclosed upfront or clearly stated

Non-Monetary Rewards

  • Public recognition (release notes)
  • ProjectDiscovery swag

How to Participate

  1. Find a bounty labeled issue
  2. Announce intent by commenting on the issue
  3. Work in public, following contribution guidelines
  4. 1 active issue per contributor at a time
  5. Complete within 2 weeks of claiming
  6. Submit a PR clearly linked to the issue
  7. Address review feedback
  8. Get merged
  9. Claim reward via provided instructions

First complete, high-quality submission wins the bounty.

Review & Evaluation

All submissions are reviewed by ProjectDiscovery maintainers.

Evaluation criteria:

  • Correctness and completeness
  • Code quality and tests
  • Adherence to project standards
  • Alignment with bounty scope

Security & Responsible Disclosure

  • Never disclose vulnerabilities publicly
  • Report security issues privately via [email protected]
  • Follow coordinated disclosure timeline
  • No exploitation, data access, or service distruption

Payments & Legal

  • Payments are typically processed within a reasonable timeframe after approval
  • Contributors are responsible for taxes and legal compliance
  • Contributions are licensed under the project’s existing open-source license
  • No employment or contractor relationship is created

Code of Conduct

All participants must:

  • Act ethically and respectfully
  • Avoid harassment, spam, or manipulation
  • Respect maintainers’ decisions
  • Keep discussions transparent and public

Violations may result in disqualification or bans.

Program Changes

ProjectDiscovery may modify or end the program at any time.

  • Changes will be announced publicly
  • In-progress accepted work will be honored whenever possible

Contact

Why This Matters

Security should be democratized.

This programs exists to:

  • Democratize security; build a healthier, more accessible security ecosystem
  • Empower independent researchers
  • Reward real-world impact
  • Strengthen open-source security tooling.

If you believe in open source security for everyone, we welcome you.

Happy Hacking!


文章来源: https://github.com/projectdiscovery/oss-bounty-program
如有侵权请联系:admin#unsafe.sh