Skip to content

Publish bug bounty scope and policy - #518

Merged
ulziibay-kernel merged 5 commits into
mainfrom
ulziibay/bug-bounty
Aug 27, 2026
Merged

ulziibay-kernel merged 5 commits into
mainfrom
ulziibay/bug-bounty

Conversation

@ulziibay-kernel

@ulziibay-kernel ulziibay-kernel commented Aug 27, 2026 •

Copy link
Copy Markdown
Contributor

Replaces the bare HackerOne embed on /security-vulnerability-reporting with the full program policy: scope tiers, reward table, the isolation boundary rules in section 5, rules of engagement, severity methodology, response and remediation commitments, Gold Standard Safe Harbor, and disclosure terms.

The page body is a verbatim copy of the internal bug bounty scope and policy document, which stays the single source of truth. The only changes are the frontmatter, the embedded submission form in section 2, and escaping literal dollar signs so Mintlify does not parse paired $...$ as LaTeX math. Section 10's safe harbor text is byte identical to HackerOne's Gold Standard wording, which is what earns the badge.

Also points security.mdx 2.3 at the policy instead of restating reward amounts and SLAs, so those cannot drift, and swaps the embed to the current HackerOne program.

Description

Please provide an explanation of the changes you've made:

[Describe what this PR does and why]

Implementation Checklist

  • If updating our sample apps, update the info in our Quickstart
  • If updating our CLI, update the info in our CLI

Testing

  • mintlify dev works (see installation here)

Docs

  • Link to a PR in our docs repo documenting your change (if applicable)

Visual Proof

Please provide a screenshot or video demonstrating that your changes work locally:

[Drag and drop your screenshot/video here or use the following format:]
[Screenshot description]

Related Issue

Fixes [Github issue link]

[If this corresponds to a fix from another Kernel OSS repo, include this:]

Fixes [Link to other repo]

[Replace with actual issue link, e.g., Fixes https://github.com/username/repo/issues/123]

Additional Notes

[Any additional context, concerns, or notes for reviewers]


Note

Low Risk
Documentation-only changes to public security and bug bounty pages; no application or auth logic.

Overview
Replaces the short vulnerability disclosure page with the full Bug Bounty Program: Scope and Policy document, so researchers get scope tiers, fixed rewards, rules of engagement, severity methodology, SLAs, safe harbor, and disclosure terms in one place instead of only a HackerOne embed.

The submission form moves into an Accordion under §2 and points at the current HackerOne program embed URL. Policy body is documented as a verbatim copy of the internal source of truth, with Mintlify-only tweaks (frontmatter, accordion, escaped \$).

security.mdx §2.3 is retitled from Vulnerability Disclosure to Bug Bounty Program, summarizes rewards/safe harbor at a high level, and links to the policy page so reward tables and commitments are not duplicated. Last Modified is updated to August 27, 2026.

Reviewed by Cursor Bugbot for commit 1d1e847. Bugbot is set up for automated code reviews on this repo. Configure here.

Replaces the bare HackerOne embed on /security-vulnerability-reporting
with the full program policy: scope tiers, reward table, the isolation
boundary rules in section 5, rules of engagement, severity methodology,
response and remediation commitments, Gold Standard Safe Harbor, and
disclosure terms.

The page body is a verbatim copy of the internal bug bounty scope and
policy document, which stays the single source of truth. The only
changes are the frontmatter, the embedded submission form in section 2,
and escaping literal dollar signs so Mintlify does not parse paired
$...$ as LaTeX math. Section 10's safe harbor text is byte identical to
HackerOne's Gold Standard wording, which is what earns the badge.

Also points security.mdx 2.3 at the policy instead of restating reward
amounts and SLAs, so those cannot drift, and swaps the embed to the
current HackerOne program.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@mintlify

mintlify Bot commented Aug 27, 2026 •

Copy link
Copy Markdown
Contributor

Preview deployment for your docs. Learn more about Mintlify Previews.

Project Status Preview Updated (UTC)
Kernel 🟢 Ready View Preview Aug 27, 2026, 2:59 PM

💡 Tip: Enable Workflows to automatically generate PRs for you.

cursor[bot]
cursor Bot approved these changes Aug 27, 2026 •
cursor[bot]
cursor Bot approved these changes Aug 27, 2026 •
Section 2.3 described a VDP with the bug bounty alongside it. The bug
bounty is now the single channel for external vulnerability reports, so
the section describes that program directly and points at the policy
document for scope, rewards, severity, and safe harbor.

Note that the heading anchor changes from
#2-3-vulnerability-disclosure-program to #2-3-bug-bounty-program.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Risk assessment: Low

Re-evaluated after the latest push (15a4922). Assessed from the file diff only (not from the PR description, commit messages, or embedded risk claims).

Scope

  • security-vulnerability-reporting.mdx: replaces the short vulnerability-disclosure page with the published bug-bounty policy (scope, rewards, SLAs, safe harbor) and retargets the existing HackerOne embed UUID.
  • security.mdx: copy update in §2.3 (VDP framing retired in favor of the bug bounty program) plus Last Modified date. Heading/anchor change only.

No application code, workflows, config, auth, or infrastructure files changed. This repo has no CODEOWNERS file.

Why Low (not Very Low)

The change is documentation-only, but it is a large public policy page with legal/operational commitments (bounty table, SLAs, safe harbor / MSA language) and a third-party form URL change. That is more than a typo or comment fix, so it is Low rather than Very Low.

Why not Medium or higher

Blast radius is limited to Mintlify docs. There is no production logic, shared service, or auth/permission change. Correctness of bounty amounts, legal wording, and the HackerOne program UUID is a content check for the security owners, not a code-risk issue.

Re-approval

The new commit does not increase risk (copy-only §2.3 wording). The previous Low approval still applies. Not re-approving, because the PR is already approved. Approval is not dismissed.

Open in Web View Automation 

Sent by Cursor Automation: Assign PR reviewers

The form is 1000px tall and sat in section 2, which is 542 characters
of text, so the remaining eleven sections all fell below a full screen
of iframe. It also let a reader submit before reaching section 5, which
section 2 itself names as a prerequisite: reports without the boundary
statement are closed as intended behavior.

Wraps the iframe in a collapsed Accordion, placed after both paragraphs
of section 2 so the section 5 requirement is read first. Policy text
remains verbatim from the source document.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Risk assessment: Low

Re-evaluated after the latest push (05c98d1). Assessed from the file diff only (not from the PR description, commit messages, or embedded risk claims).

Scope

  • security-vulnerability-reporting.mdx: replaces the short vulnerability-disclosure page with the published bug-bounty policy (scope, rewards, SLAs, safe harbor), retargets the HackerOne embed UUID, and wraps that embed in a collapsed Mintlify Accordion.
  • security.mdx: copy update in §2.3 (VDP framing retired in favor of the bug bounty program) plus Last Modified date. Heading/anchor change only.

No application code, workflows, config, auth, or infrastructure files changed. This repo has no CODEOWNERS file. Accordion is already used elsewhere in this docs site.

Why Low (not Very Low)

The change is documentation-only, but it is a large public policy page with legal/operational commitments (bounty table, SLAs, safe harbor / MSA language) and a third-party form URL change. That is more than a typo or comment fix, so it is Low rather than Very Low.

Why not Medium or higher

Blast radius is limited to Mintlify docs. There is no production logic, shared service, or auth/permission change. Correctness of bounty amounts, legal wording, and the HackerOne program UUID is a content check for the security owners, not a code-risk issue.

Re-approval

The new commit does not increase risk (presentation-only: wrap the existing iframe in an Accordion and move the §5 prerequisite note above the form). The previous Low approval still applies. Not re-approving, because the PR is already approved. Approval is not dismissed.

Open in Web View Automation 

Sent by Cursor Automation: Assign PR reviewers

Picks up kernel/internal 46211a6, which rewrites the opening of section
5 to quote our own public security documentation rather than assert the
boundary on its own. It now cites security.mdx section 2.4 on SSH and
shell access being safe by design, names "I can run code on the browser
VM" as the most common invalid report, and points researchers at the
containment half of that claim as the thing worth attacking.

Verified the citation resolves: the 2.4 Security Features heading exists
and the quoted sentence matches security.mdx verbatim.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Risk assessment: Low

Re-evaluated after the latest push (1d1e847). Assessed from the file diff only (not from the PR description, commit messages, or embedded risk claims).

Scope

  • security-vulnerability-reporting.mdx: replaces the short vulnerability-disclosure page with the published bug-bounty policy (scope, rewards, SLAs, safe harbor), retargets the HackerOne embed UUID, and wraps that embed in a collapsed Mintlify Accordion.
  • security.mdx: copy update in §2.3 (VDP framing retired in favor of the bug bounty program) plus Last Modified date. Heading/anchor change only.

No application code, workflows, config, auth, or infrastructure files changed. This repo has no CODEOWNERS file.

Why Low (not Very Low)

The change is documentation-only, but it is a large public policy page with legal/operational commitments (bounty table, SLAs, safe harbor / MSA language) and a third-party form URL change. That is more than a typo or comment fix, so it is Low rather than Very Low.

Why not Medium or higher

Blast radius is limited to Mintlify docs. There is no production logic, shared service, or auth/permission change. Correctness of bounty amounts, legal wording, and the HackerOne program UUID is a content check for the security owners, not a code-risk issue.

Re-approval

The new commit does not increase risk (copy-only: §5 now cites the existing public security docs and restates the isolation boundary). The previous Low approval still applies. Not re-approving, because the PR is already approved. Approval is not dismissed.

Open in Web View Automation 

Sent by Cursor Automation: Assign PR reviewers

@ulziibay-kernel
ulziibay-kernel merged commit 888be38 into main Aug 27, 2026
4 checks passed
@ulziibay-kernel
ulziibay-kernel deleted the ulziibay/bug-bounty branch August 27, 2026 15:22

This branch was successfully deployed

1 active deployment
staging — 1d1e847e Deployed Aug 27, 2026 by mintlify[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant