File tree Expand file tree Collapse file tree 1 file changed +36
-0
lines changed
apps/site/pages/en/blog/announcements Expand file tree Collapse file tree 1 file changed +36
-0
lines changed Original file line number Diff line number Diff line change 1+ ---
2+ date : 2026-01-20T12:00:00.000Z
3+ category : announcements
4+ title : New HackerOne Signal Requirement for Vulnerability Reports
5+ layout : blog-post
6+ author : The Node.js Project
7+ ---
8+
9+ We have updated our [ HackerOne program] ( https://hackerone.com/nodejs ) to require a ** Signal of 1.0 or
10+ higher** to submit vulnerability reports to the Node.js project.
11+
12+ ## Why This Change
13+
14+ The Node.js security team has experienced a significant increase in low-quality, AI-generated vulnerability
15+ reports. Triaging these reports consumes time and energy that could be spent on legitimate security work.
16+ We consider this volume of noise a denial-of-service against the project's security process.
17+
18+ By requiring a minimum Signal score, we ensure that reporters have a proven track record of submitting
19+ valid security reports, while still allowing newer researchers to participate with a limited number of
20+ submissions.
21+
22+ ## What This Means for You
23+
24+ - ** Researchers with Signal >= 1.0** : You can continue reporting vulnerabilities through HackerOne as usual
25+ - ** New researchers or those below the threshold** : You can still reach the security team through the
26+ [ OpenJS Foundation Slack] ( https://slack-invite.openjsf.org/ ) . Contact us there to discuss potential
27+ vulnerabilities
28+
29+ ## About HackerOne Signal
30+
31+ Signal is HackerOne's reputation metric that reflects the quality of a researcher's past submissions.
32+ A higher Signal indicates a history of valid, impactful reports. This requirement helps us prioritize
33+ reports from researchers with demonstrated expertise while reducing the burden of triaging invalid
34+ submissions.
35+
36+ We appreciate the security community's understanding and continued collaboration in keeping Node.js secure.
You can’t perform that action at this time.
0 commit comments