deniz.in

Markets

Weather

Loading weather

· via Vercel blog

Vercel merges private and open-source bug bounties into one public program

Vercel has folded its private and open-source bug bounty efforts into a single public program on HackerOne, arguing that AI-expanded public research still surfaces real vulnerabilities.

Vercel merges private and open-source bug bounties into one public program

Vercel consolidates its bug bounties into one public program

Vercel has merged its private bug bounty program and its separate open-source bounty effort into a single program that is now open to the public, according to an announcement on the Vercel blog. All submissions run through HackerOne, the platform Vercel has used since launching a private program in 2022.

Vercel says the private program was operated through HackerOne's VIP offering, which let the company bring on thousands of vetted researchers over several years while it refined its targets, scope and processes. That experience, along with running several large public programs recently, is what the company points to as evidence it can now handle a fully public one.

Going public in the age of AI-generated reports

The reasoning behind the change is the notable part. Vercel says AI has reshaped bug bounty work by dramatically increasing the volume of reports, both genuine and spurious, and that some companies have responded by pulling back into private, invitation-only programs. Vercel is deliberately moving in the opposite direction.

The company's position is that public reports are still turning up real and valuable findings, that AI lets a much wider range of researchers discover vulnerabilities, and that each report should be evaluated on its own merit. To absorb the expected flood of low-quality submissions, Vercel says its security engineering team has streamlined the workflow and built tooling to filter out noise and speed up fixes, with improvements at every stage from triage to shipping and verifying patches.

What is covered and how to take part

According to the announcement, all products across the Vercel platform and its open-source projects now sit under the unified public program, with full details listed on the program's scope page on HackerOne. The consolidation also answers feedback from the research community, which had found it confusing to have multiple places to submit reports.

There are two practical details for researchers:

  • New findings in Vercel's open-source projects should be reported to the main Vercel program.
  • Existing submissions to the previous OSS program do not need to be resubmitted; Vercel says every one will still be reviewed.

To participate, researchers file reports through HackerOne with clear reproduction steps. Vercel says its security team reviews each submission, coordinates with researchers through the disclosure process, and is committing to fast response times and transparent communication. Nothing changes for researchers already active in the private program, the company adds, and it is also hiring for its security team.

Why it matters

Vercel is a major deployment platform, which means vulnerabilities in its products or its open-source tooling could ripple out to a large number of production sites and applications. Opening the bounty to anyone widens the set of eyes on that surface well beyond an invited list.

The move is also a counterpoint to a visible trend: if AI-driven report spam is pushing other vendors toward closed programs, Vercel is betting that better filtering and triage tooling can keep public programs viable. How well that bet holds up, and whether other platforms follow, will say a lot about the future shape of coordinated disclosure. For researchers, the practical effect is immediate: a single place to report, one process to learn, and published scope covering the entire platform.

  • #vercel
  • #security
  • #bug-bounty
  • #hackerone
  • #cloud

Related posts