Bug Triage and Reporting
Why 2022 was a record-breaking year in bug bounty awards

Why 2022 was a record-breaking year in bug bounty awards

12/19/2022 · Nick Malcolm

What this post added

This post details the record-breaking year for GitLab's bug bounty program in 2022, highlighting the total amount awarded ($1,055,770 USD across 221 valid reports), the number of reports received (920 from 424 researchers), and the number of resolved and public reports. It also recognizes top researchers for their contributions, including the most valid reports, most valid reports from a newcomer, best written report, most innovative report, and most impactful finding. Changes made in 2022 include adopting HackerOne's Gold Standard Safe Harbor, introducing a $20,000 CTF bonus, creating HackerOne Questions for direct communication, developing 'Reproducible Vulnerabilities' as a learning resource, and iterating on the HackerOne triage process and Bug Bounty Calculator for transparency and standardization.

Read the original post ↗