|
| 1 | +--- |
| 2 | +date: 2026-01-21T12:00:00.000Z |
| 3 | +category: announcements |
| 4 | +title: New HackerOne Signal Requirement for Vulnerability Reports |
| 5 | +layout: blog-post |
| 6 | +author: The Node.js Project |
| 7 | +--- |
| 8 | + |
| 9 | +We have updated our [HackerOne program](https://hackerone.com/nodejs) to require a **Signal of 1.0 or |
| 10 | +higher** to submit vulnerability reports to the Node.js project. |
| 11 | + |
| 12 | +## Why This Change |
| 13 | + |
| 14 | +The Node.js security team has experienced a significant increase in low-quality reports. |
| 15 | +This trend has been increasing over the years, and over the holidays it crossed the threshold |
| 16 | +that we can actually handle. Between December 15th and January 15th, we received over 30 reports. |
| 17 | +Triaging these reports consumes time and energy that could be spent on legitimate security work. |
| 18 | + |
| 19 | +By requiring a minimum Signal score, we ensure that reporters have a proven track record of submitting |
| 20 | +valid security reports, while still allowing newer researchers to participate with a limited number of |
| 21 | +submissions. |
| 22 | + |
| 23 | +## What This Means for You |
| 24 | + |
| 25 | +- **New researchers or researchers with [signal][Signal] >= 1.0**: You can continue reporting vulnerabilities through HackerOne as usual |
| 26 | +- **Those below the threshold**: You can still reach the security team through the |
| 27 | + [OpenJS Foundation Slack](https://slack-invite.openjsf.org/). Contact us there to discuss potential |
| 28 | + vulnerabilities |
| 29 | + |
| 30 | +## About HackerOne Signal |
| 31 | + |
| 32 | +[Signal][] is HackerOne's reputation metric that reflects the quality of a researcher's past submissions. |
| 33 | +A higher Signal indicates a history of valid, impactful reports. This requirement helps us prioritize |
| 34 | +reports from researchers with demonstrated expertise while reducing the burden of triaging invalid |
| 35 | +submissions. |
| 36 | + |
| 37 | +We appreciate the security community's understanding and continued collaboration in keeping Node.js secure. |
| 38 | + |
| 39 | +[Signal]: https://docs.hackerone.com/en/articles/8369891-signal-impact |
0 commit comments