logo

Node.js Updated HackerOne Program to Require a Signal of 1.0 or Higher to Submit Vulnerability Reports

ID: ed727cfe-1626-56aa-a378-2673b238992b

STIX ID: report--ed727cfe-1626-56aa-a378-2673b238992b

Feed Name: cybersecurityNews.com

Date Published: 2026-01-23

Date Updated: 2026-04-21

Author: Abinaya

...
...

Node.js has tightened its HackerOne vulnerability disclosure program by requiring a minimum Signal score of 1.0 to mitigate low-quality reports and improve processing efficiency after a spike in weak submissions. Researchers meeting the threshold can submit as usual, while those below it are encouraged to engage via the OpenJS Foundation Slack to establish credibility and understand expectations, reflecting a broader trend toward quality controls in bug bounty ecosystems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.