Skip to content

Commit e636642

Browse files
committed
Blog: add HackerOne signal 1 post
1 parent 46e0f2b commit e636642

File tree

1 file changed

+36
-0
lines changed

1 file changed

+36
-0
lines changed
Lines changed: 36 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,36 @@
1+
---
2+
date: 2026-01-20T12:00:00.000Z
3+
category: announcements
4+
title: New HackerOne Signal Requirement for Vulnerability Reports
5+
layout: blog-post
6+
author: The Node.js Project
7+
---
8+
9+
We have updated our [HackerOne program](https://hackerone.com/nodejs) to require a **Signal of 1.0 or
10+
higher** to submit vulnerability reports to the Node.js project.
11+
12+
## Why This Change
13+
14+
The Node.js security team has experienced a significant increase in low-quality, AI-generated vulnerability
15+
reports. Triaging these reports consumes time and energy that could be spent on legitimate security work.
16+
We consider this volume of noise a denial-of-service against the project's security process.
17+
18+
By requiring a minimum Signal score, we ensure that reporters have a proven track record of submitting
19+
valid security reports, while still allowing newer researchers to participate with a limited number of
20+
submissions.
21+
22+
## What This Means for You
23+
24+
- **Researchers with Signal >= 1.0**: You can continue reporting vulnerabilities through HackerOne as usual
25+
- **New researchers or those below the threshold**: You can still reach the security team through the
26+
[OpenJS Foundation Slack](https://slack-invite.openjsf.org/). Contact us there to discuss potential
27+
vulnerabilities
28+
29+
## About HackerOne Signal
30+
31+
Signal is HackerOne's reputation metric that reflects the quality of a researcher's past submissions.
32+
A higher Signal indicates a history of valid, impactful reports. This requirement helps us prioritize
33+
reports from researchers with demonstrated expertise while reducing the burden of triaging invalid
34+
submissions.
35+
36+
We appreciate the security community's understanding and continued collaboration in keeping Node.js secure.

0 commit comments

Comments
 (0)