HackerOne offers free bug bounty service for open-source projects
Bug bounty startup HackerOne Inc. is giving back to the open-source community with a new program that provides its professional suite for free to qualifying projects.
Dubbed the HackerOne Community Program, the program is open to open-source projects that are licensed under an Open Source Initiative license and have been active for at least three months. In addition, the projects are required to add a “SECURITY.md” file to their project root to provide details on submitting vulnerabilities, advertise the bug bounty program on their website and commit to responding to new bug reports within a week.
Founded in 2012, HackerOne offers a cloud-based bug bounty platform knows as Security@ that provides access to a community of more than 100,000 vulnerability assessment professionals that organizations can ask to look for weaknesses in their technology infrastructure. It’s already being used by open-source projects such as Ruby, Rails, Discourse, Django, GitLab, Brave and Sentry.
The program will provide the same vulnerability submission coordination, de-duplication service, analytics and bounty programs for projects offered by the paid version. But it will not include customer support and will still see HackerOne charging its usual 20 percent payment processing fee on all cash bounties paid.
HackerOne Chief Executive Officer Marten Mickos claims that the program is the first of its kind. He said the company was aiming to ensure that open-source projects received as much support as possible when it comes to running simple, efficient and productive security programs.
“Our company, product, and approach is built-on, inspired by, and driven by open source and a culture of collaborative software development,” Mickos said in an announcement post.
The company raised $40 million in a late-stage round announced last month.
Image: Pixabay
Since you’re here …
… We’d like to tell you about our mission and how you can help us fulfill it. SiliconANGLE Media Inc.’s business model is based on the intrinsic value of the content, not advertising. Unlike many online publications, we don’t have a paywall or run banner advertising, because we want to keep our journalism open, without influence or the need to chase traffic.The journalism, reporting and commentary on SiliconANGLE — along with live, unscripted video from our Silicon Valley studio and globe-trotting video teams at theCUBE — take a lot of hard work, time and money. Keeping the quality high requires the support of sponsors who are aligned with our vision of ad-free journalism content.
If you like the reporting, video interviews and other ad-free content here, please take a moment to check out a sample of the video content supported by our sponsors, tweet your support, and keep coming back to SiliconANGLE.