UPDATED 21:51 EST / MARCH 05 2017

INFRA

HackerOne offers free bug bounty service for open-source projects

Bug bounty startup HackerOne Inc. is giving back to the open-source community with a new program that provides its professional suite for free to qualifying projects.

Dubbed the HackerOne Community Program, the program is open to open-source projects that are licensed under an Open Source Initiative license and have been active for at least three months. In addition, the projects are required to add a “SECURITY.md” file to their project root to provide details on submitting vulnerabilities, advertise the bug bounty program on their website and commit to responding to new bug reports within a week.

Founded in 2012, HackerOne offers a cloud-based bug bounty platform knows as Security@ that provides access to a community of more than 100,000 vulnerability assessment professionals that organizations can ask to look for weaknesses in their technology infrastructure. It’s already being used by open-source projects such as Ruby, Rails, Discourse, Django, GitLab, Brave and Sentry.

The program will provide the same vulnerability submission coordination, de-duplication service, analytics and bounty programs for projects offered by the paid version. But it will not include customer support and will still see HackerOne charging its usual 20 percent payment processing fee on all cash bounties paid.

HackerOne Chief Executive Officer Marten Mickos claims that the program is the first of its kind. He said the company was aiming to ensure that open-source projects received as much support as possible when it comes to running simple, efficient and productive security programs.

“Our company, product, and approach is built-on, inspired by, and driven by open source and a culture of collaborative software development,” Mickos said in an announcement post.

The company raised $40 million in a late-stage round announced last month.

Image: Pixabay

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.