
3/11/2021
What this post added
This post details several key updates and improvements to Shopify's Bug Bounty program in 2021. It highlights the success of the H1-2102 Virtual Live Hacking Event, significant bounty milestones including over $2 million awarded in total and over $460,000 in 2020, and the adoption of the Common Vulnerability Scoring System (CVSS) for bounty calculation, including the release of a public calculator. A GraphQL Hacking Guide was released to aid researchers. Program improvements include the creation of a dedicated Bug Bounty Team to improve response times, the expansion of Bug Bounty Resources on GitHub, enhanced follow-up responses for hacker inquiries, and the relaunch of the Shopify Experiments private program with new criteria for invitations. The post also presents 2020 Bug Bounty Statistics, showing a substantial increase in report volume.