Announcing the ProjectDiscovery OSS Bounty Program
好的,我现在需要帮用户总结一篇文章,控制在100字以内。用户的要求很明确,直接写文章描述,不需要特定的开头。首先,我得通读整篇文章,抓住主要信息。 文章标题是“Democratizing Security, One Contribution at a Time”,看起来是关于开源安全项目的。内容提到ProjectDiscovery推出了一个OSS Bounty Program,奖励对开源安全工具的贡献。目标是让安全工具更普及,不论个人背景如何。 接下来,文章详细说明了奖励的类型:修复bug、性能提升、功能实现、文档和测试等。金额根据复杂度和影响而定。参与方式简单,浏览带标签的问题,提交pull request即可。 还有提到项目的范围包括多个开源项目,并强调透明、公平、尊重和社区的原则。最后鼓励大家参与,共同推动开源安全的发展。 现在我要把这些要点浓缩到100字以内。重点包括项目名称、目标、奖励类型、参与方式以及核心原则。确保语言简洁明了,直接传达主要内容。 </think> ProjectDiscovery推出开源安全工具贡献奖励计划,旨在通过激励全球开发者修复漏洞、优化性能及完善功能等贡献,推动安全工具普及化和社区协作。该计划强调透明、公平和尊重原则,欢迎所有背景的参与者共同参与开源安全建设。 2026-2-2 14:17:38 Author: projectdiscovery.io(查看原文) 阅读量:1 收藏

Democratizing Security, One Contribution at a Time

Today, we're excited to announce the launch of the ProjectDiscovery OSS Bounty Program, a new initiative to reward meaningful contributions to our open-source security tools.

The Vision

At ProjectDiscovery, we've always believed that security should be accessible to everyone. Our tools are used by researchers, defenders, and builders worldwide. From Fortune 500 security teams to independent bug bounty hunters, from government agencies to open-source enthusiasts, our community spans the globe. They're open source because we believe the best security tools should be available to all, not locked behind enterprise paywalls.

But open source isn't just about making code available. It's about building together.

The security community is global. Talented researchers and developers exist in every corner of the world. From São Paulo to Singapore, from Lagos to London, from Jaipur to Diyarbakir. Yet, barriers to participation remain: geographic limitations, lack of formal credentials, or simply not knowing where to start.

The OSS Bounty Program is our answer to this challenge.

What We're Launching

Starting today, contributors can earn rewards for:

  • Bug fixes - Help us squash confirmed issues
  • Performance improvements - Make our tools faster and more efficient
  • Feature implementations - Build what the community needs
  • Documentation and testing - Quality contributions that help everyone

Bounty amounts vary by complexity and impact; each issue shows the reward upfront. Every contribution that makes our tools better deserves recognition.

How It Works

We've designed the program to be straightforward:

  1. Browse issues labeled bounty in our repositories
  2. Claim an issue by commenting your intent
  3. Work openly, following our contribution guidelines
  4. Submit a pull request linked to the issue
  5. Get reviewed and address any feedback
  6. Get rewarded once your contribution is merged

No formal applications. No gatekeeping. If you can ship quality code that improves our tools, you're in.

Why Now?

Over the past few years, we've seen incredible contributions from our community. Researchers have found and reported vulnerabilities. Developers have submitted patches that made Nuclei faster and more reliable. Community members have improved our documentation and templates.

Many of these contributions came from individuals who weren't part of any formal program; they simply cared about making security tools better.

We want to do more for these contributors. The OSS Bounty Program formalizes our commitment to recognizing and rewarding the people who help build ProjectDiscovery.

Our Commitment

This program is built on a few core principles:

Transparency - Bounty amounts are clearly stated. Evaluation criteria are public. Decisions are explained.
Fairness - Anyone can participate, regardless of location, background, or credentials. Quality of contribution is what matters.
Respect - We value your time. We commit to timely reviews, clear communication, and prompt payment.
Community - This isn't transactional. We're building a community of contributors who share our mission of democratizing security.

What's In Scope

The program currently covers our major open-source projects:

  • Nuclei
  • Katana
  • Subfinder
  • Httpx
  • Naabu
  • ShuffleDNS
  • DNSx
  • TLSx
  • Vulnx
  • URLFinder

Additional repositories may be added over time. Look for the bounty label to identify eligible issues.

Get Started

Ready to contribute? Here's how:

  1. Read the full program guidelines - github.com/projectdiscovery/oss-bounty-program
  2. Browse open bounties - Check the bounty label across our repositories
  3. Join our Discord - Connect with other contributors and maintainers
  4. Start contributing - Pick an issue, claim it, and ship it

A Note on Security Research

For security vulnerabilities, we maintain a separate responsible disclosure process. Please report security issues privately to [email protected] before any public disclosure. We're committed to working with researchers in good faith and will not pursue legal action against those who follow responsible disclosure practices.

Security bounties are evaluated based on severity, impact, and quality of the report. Critical vulnerabilities in our core tools can receive meaningful rewards.

Join Us

Security shouldn't be a privilege. The best tools should be open. The best contributors should be rewarded, no matter where they come from.

If you believe in open-source security for everyone, we welcome you.

Happy Hacking!

The ProjectDiscovery Team


文章来源: https://projectdiscovery.io/blog/announcing-the-projectdiscovery-oss-bounty-program
如有侵权请联系:admin#unsafe.sh