Skip to content

Add GitHub Bug Bounty Program support documentation - #1

Draft
juanaquas with Copilot wants to merge 2 commits into
mainfrom
copilot/fix-graphql-auth-flaws
Draft

Add GitHub Bug Bounty Program support documentation#1
juanaquas with Copilot wants to merge 2 commits into
mainfrom
copilot/fix-graphql-auth-flaws

Conversation

Copilot AI commented Mar 1, 2026

Copy link
Copy Markdown

Adds security policy and vulnerability reporting infrastructure for Copilot CLI's participation in GitHub's Bug Bounty Program.

Changes

  • SECURITY.md: Security policy with HackerOne integration, scope definitions, safe harbor provisions, and reporting guidelines
  • .github/ISSUE_TEMPLATE/security_report.yml: Issue template for low-severity security concerns (critical vulns directed to HackerOne)
  • README.md: Added Security section linking to policy

Scope Definition

In scope: CLI application, auth/authz, data handling, MCP server security, plugins, session management

Out of scope: Third-party dependencies, social engineering, DoS, backend services (separate bounty)


💡 You can make Copilot smarter by setting up custom instructions, customizing its development environment and configuring Model Context Protocol (MCP) servers. Learn more Copilot coding agent tips in the docs.

Copilot AI changed the title [WIP] Fix authentication flaws in GraphQL API No changes made - Request declined Mar 1, 2026
…emplate

Co-authored-by: juanaquas <264702634+juanaquas@users.noreply.github.com>
Copilot AI changed the title No changes made - Request declined Add GitHub Bug Bounty Program support documentation Mar 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants