Blog from GitHub Security Lab.
GitHub public repositories matching the '#security' topic.
GitHub public repositories matching the '#pentesting' topic.
The CodeQL Bug Bounty program operated by the GitHub Security Lab aims at scaling the security research community’s work across open source projects. The All For One protects against future vulnerabilities by coding and eradicating a pattern, while the Bug Slayer fixes existing occurrences of this pattern. A bounty hunter can apply to both programs sequentially to maximize their positive impact on open source projects, and their gain.
GitHub public repositories matching the '#redteam' topic.
GitHub public repositories matching the '#hacking' topic.
GitHub public repositories matching the '#malware' topic.
Do you want to challenge your vulnerability hunting skills? We created these CTF challenges to allow you to do exactly that, while helping you to quickly learn CodeQL.
GitHub Security Lab researchers find vulnerabilities in key, widely-used open source projects. We then coordinate the disclosure of those vulnerabilities to security teams at those projects. We only publish vulnerabilities here after they’ve been announced by the affected projects' development teams and patches are available. See our disclosure policy below for more information.
GitHub public repositories matching the '#reverse-engineering' topic.