logo

Node.js Sets New Standard for HackerOne Reports, Demands Signal of 1.0 or Higher

ID: 4e4f9ecf-89ce-5747-89b6-461ada261956

STIX ID: report--4e4f9ecf-89ce-5747-89b6-461ada261956

Feed Name: GBHackers

Date Published: 2026-01-23

Date Updated: 2026-04-22

Author: Divya

...
...

Node.js, via the OpenJS Foundation, has updated its HackerOne bug bounty rules to require a minimum Signal score of 1.0 for direct vulnerability submissions, aiming to reduce low-quality reports that have overwhelmed triage resources. Researchers below the threshold can still engage through the OpenJS Foundation Slack to discuss potential issues, maintaining accessibility while improving the signal-to-noise ratio and response times for critical vulnerabilities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.