HackerOne Enhances IBB Project To Help Open Source Security

September 22, 2021

HackerOne has expanded the Internet Bug Bounty (IBB) project to improve general open source security.

Open source projects, spearheaded by individuals and development teams around the world, are supported by almost everyone, from enterprise players to SMBs.

A recent survey conducted by the Linux Foundation and edX found that demand for open-source programmers and experts is soaring, but 92% of managers are having difficulty finding the talent needed to fill current vacancies.

Combined with a skills shortage and the fact that many open source projects are run by developers who are not compensated for their efforts, this can lead to security issues slipping through the net.

The IBB can help solve some of these issues. The IBB is now managed by HackerOne and described as a project that “pool funding and incentivize security researchers to report vulnerabilities within open source software.”

There are three major changes: HackerOne customers can now pool between 1% and 10% of their existing expenditure on the open-source project – of which they may be using components on a large scale – and bounties are now divided 80/20 among hackers and maintainers.

The third amendment is a simplified system for submitting vulnerability reports.

Since its launch in 2013, more than 1,000 vulnerabilities have been reported, with about 300 bug bounty hunters receiving financial awards of approximately $900,000.

Current projects include Ruby, Node.js, Python, Django, and Curl, with more options to be launched soon.

For more information, read the original story in ZDNet.

Top Stories

Related Articles

August 25, 2025 xAI has announced that they are issuing and Open-Source version of Grok 2.5 — a move likely intended more...

June 15, 2025 A new Linux Foundation report reveals that 89% of organizations using artificial intelligence (AI) have adopted open more...

March 30, 2025 Cloudflare has released an open-source tool called OPKSSH (OpenPubkey SSH), which allows developers and IT teams to more...

March 16, 2025 Windows 10 will cease receiving security updates after October 2025, and this means charities and non-profit organizations more...

Jim Love

Jim is an author and podcast host with over 40 years in technology.

Share:
Facebook
Twitter
LinkedIn