Skip to content

Commit dbf3711

Browse files
RafaelGSSaduh95
andauthored
Blog: Add hackerone new policy (#8559)
* Blog: add HackerOne signal 1 post * Apply suggestions from code review Co-authored-by: Antoine du Hamel <duhamelantoine1995@gmail.com> * fixup! Blog: add HackerOne signal 1 post * fixup! fixup! Blog: add HackerOne signal 1 post --------- Co-authored-by: Antoine du Hamel <duhamelantoine1995@gmail.com>
1 parent 79d8c91 commit dbf3711

File tree

1 file changed

+39
-0
lines changed

1 file changed

+39
-0
lines changed
Lines changed: 39 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,39 @@
1+
---
2+
date: 2026-01-21T12:00:00.000Z
3+
category: announcements
4+
title: New HackerOne Signal Requirement for Vulnerability Reports
5+
layout: blog-post
6+
author: The Node.js Project
7+
---
8+
9+
We have updated our [HackerOne program](https://hackerone.com/nodejs) to require a **Signal of 1.0 or
10+
higher** to submit vulnerability reports to the Node.js project.
11+
12+
## Why This Change
13+
14+
The Node.js security team has experienced a significant increase in low-quality reports.
15+
This trend has been increasing over the years, and over the holidays it crossed the threshold
16+
that we can actually handle. Between December 15th and January 15th, we received over 30 reports.
17+
Triaging these reports consumes time and energy that could be spent on legitimate security work.
18+
19+
By requiring a minimum Signal score, we ensure that reporters have a proven track record of submitting
20+
valid security reports, while still allowing newer researchers to participate with a limited number of
21+
submissions.
22+
23+
## What This Means for You
24+
25+
- **New researchers or researchers with [signal][Signal] >= 1.0**: You can continue reporting vulnerabilities through HackerOne as usual
26+
- **Those below the threshold**: You can still reach the security team through the
27+
[OpenJS Foundation Slack](https://slack-invite.openjsf.org/). Contact us there to discuss potential
28+
vulnerabilities
29+
30+
## About HackerOne Signal
31+
32+
[Signal][] is HackerOne's reputation metric that reflects the quality of a researcher's past submissions.
33+
A higher Signal indicates a history of valid, impactful reports. This requirement helps us prioritize
34+
reports from researchers with demonstrated expertise while reducing the burden of triaging invalid
35+
submissions.
36+
37+
We appreciate the security community's understanding and continued collaboration in keeping Node.js secure.
38+
39+
[Signal]: https://docs.hackerone.com/en/articles/8369891-signal-impact

0 commit comments

Comments
 (0)