Repository navigation
Publish bug bounty scope and policy - #518
Conversation
Replaces the bare HackerOne embed on /security-vulnerability-reporting with the full program policy: scope tiers, reward table, the isolation boundary rules in section 5, rules of engagement, severity methodology, response and remediation commitments, Gold Standard Safe Harbor, and disclosure terms. The page body is a verbatim copy of the internal bug bounty scope and policy document, which stays the single source of truth. The only changes are the frontmatter, the embedded submission form in section 2, and escaping literal dollar signs so Mintlify does not parse paired $...$ as LaTeX math. Section 10's safe harbor text is byte identical to HackerOne's Gold Standard wording, which is what earns the badge. Also points security.mdx 2.3 at the policy instead of restating reward amounts and SLAs, so those cannot drift, and swaps the embed to the current HackerOne program. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Preview deployment for your docs. Learn more about Mintlify Previews.
💡 Tip: Enable Workflows to automatically generate PRs for you. |
Section 2.3 described a VDP with the bug bounty alongside it. The bug bounty is now the single channel for external vulnerability reports, so the section describes that program directly and points at the policy document for scope, rewards, severity, and safe harbor. Note that the heading anchor changes from #2-3-vulnerability-disclosure-program to #2-3-bug-bounty-program. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
There was a problem hiding this comment.
Stale comment
Risk assessment: Low
Re-evaluated after the latest push (
15a4922). Assessed from the file diff only (not from the PR description, commit messages, or embedded risk claims).Scope
security-vulnerability-reporting.mdx: replaces the short vulnerability-disclosure page with the published bug-bounty policy (scope, rewards, SLAs, safe harbor) and retargets the existing HackerOne embed UUID.security.mdx: copy update in §2.3 (VDP framing retired in favor of the bug bounty program) plus Last Modified date. Heading/anchor change only.No application code, workflows, config, auth, or infrastructure files changed. This repo has no CODEOWNERS file.
Why Low (not Very Low)
The change is documentation-only, but it is a large public policy page with legal/operational commitments (bounty table, SLAs, safe harbor / MSA language) and a third-party form URL change. That is more than a typo or comment fix, so it is Low rather than Very Low.
Why not Medium or higher
Blast radius is limited to Mintlify docs. There is no production logic, shared service, or auth/permission change. Correctness of bounty amounts, legal wording, and the HackerOne program UUID is a content check for the security owners, not a code-risk issue.
Re-approval
The new commit does not increase risk (copy-only §2.3 wording). The previous Low approval still applies. Not re-approving, because the PR is already approved. Approval is not dismissed.
Sent by Cursor Automation: Assign PR reviewers
The form is 1000px tall and sat in section 2, which is 542 characters of text, so the remaining eleven sections all fell below a full screen of iframe. It also let a reader submit before reaching section 5, which section 2 itself names as a prerequisite: reports without the boundary statement are closed as intended behavior. Wraps the iframe in a collapsed Accordion, placed after both paragraphs of section 2 so the section 5 requirement is read first. Policy text remains verbatim from the source document. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
There was a problem hiding this comment.
Stale comment
Risk assessment: Low
Re-evaluated after the latest push (
05c98d1). Assessed from the file diff only (not from the PR description, commit messages, or embedded risk claims).Scope
security-vulnerability-reporting.mdx: replaces the short vulnerability-disclosure page with the published bug-bounty policy (scope, rewards, SLAs, safe harbor), retargets the HackerOne embed UUID, and wraps that embed in a collapsed MintlifyAccordion.security.mdx: copy update in §2.3 (VDP framing retired in favor of the bug bounty program) plus Last Modified date. Heading/anchor change only.No application code, workflows, config, auth, or infrastructure files changed. This repo has no CODEOWNERS file.
Accordionis already used elsewhere in this docs site.Why Low (not Very Low)
The change is documentation-only, but it is a large public policy page with legal/operational commitments (bounty table, SLAs, safe harbor / MSA language) and a third-party form URL change. That is more than a typo or comment fix, so it is Low rather than Very Low.
Why not Medium or higher
Blast radius is limited to Mintlify docs. There is no production logic, shared service, or auth/permission change. Correctness of bounty amounts, legal wording, and the HackerOne program UUID is a content check for the security owners, not a code-risk issue.
Re-approval
The new commit does not increase risk (presentation-only: wrap the existing iframe in an Accordion and move the §5 prerequisite note above the form). The previous Low approval still applies. Not re-approving, because the PR is already approved. Approval is not dismissed.
Sent by Cursor Automation: Assign PR reviewers
Picks up kernel/internal 46211a6, which rewrites the opening of section 5 to quote our own public security documentation rather than assert the boundary on its own. It now cites security.mdx section 2.4 on SSH and shell access being safe by design, names "I can run code on the browser VM" as the most common invalid report, and points researchers at the containment half of that claim as the thing worth attacking. Verified the citation resolves: the 2.4 Security Features heading exists and the quoted sentence matches security.mdx verbatim. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
There was a problem hiding this comment.
Risk assessment: Low
Re-evaluated after the latest push (1d1e847). Assessed from the file diff only (not from the PR description, commit messages, or embedded risk claims).
Scope
security-vulnerability-reporting.mdx: replaces the short vulnerability-disclosure page with the published bug-bounty policy (scope, rewards, SLAs, safe harbor), retargets the HackerOne embed UUID, and wraps that embed in a collapsed MintlifyAccordion.security.mdx: copy update in §2.3 (VDP framing retired in favor of the bug bounty program) plus Last Modified date. Heading/anchor change only.
No application code, workflows, config, auth, or infrastructure files changed. This repo has no CODEOWNERS file.
Why Low (not Very Low)
The change is documentation-only, but it is a large public policy page with legal/operational commitments (bounty table, SLAs, safe harbor / MSA language) and a third-party form URL change. That is more than a typo or comment fix, so it is Low rather than Very Low.
Why not Medium or higher
Blast radius is limited to Mintlify docs. There is no production logic, shared service, or auth/permission change. Correctness of bounty amounts, legal wording, and the HackerOne program UUID is a content check for the security owners, not a code-risk issue.
Re-approval
The new commit does not increase risk (copy-only: §5 now cites the existing public security docs and restates the isolation boundary). The previous Low approval still applies. Not re-approving, because the PR is already approved. Approval is not dismissed.
Sent by Cursor Automation: Assign PR reviewers


Replaces the bare HackerOne embed on /security-vulnerability-reporting with the full program policy: scope tiers, reward table, the isolation boundary rules in section 5, rules of engagement, severity methodology, response and remediation commitments, Gold Standard Safe Harbor, and disclosure terms.
The page body is a verbatim copy of the internal bug bounty scope and policy document, which stays the single source of truth. The only changes are the frontmatter, the embedded submission form in section 2, and escaping literal dollar signs so Mintlify does not parse paired$...$ as LaTeX math. Section 10's safe harbor text is byte identical to HackerOne's Gold Standard wording, which is what earns the badge.
Also points security.mdx 2.3 at the policy instead of restating reward amounts and SLAs, so those cannot drift, and swaps the embed to the current HackerOne program.
Description
Please provide an explanation of the changes you've made:
[Describe what this PR does and why]
Implementation Checklist
Testing
mintlify devworks (see installation here)Docs
Visual Proof
Please provide a screenshot or video demonstrating that your changes work locally:
[Drag and drop your screenshot/video here or use the following format:]
]
[
Related Issue
Fixes [Github issue link]
[If this corresponds to a fix from another Kernel OSS repo, include this:]
Fixes [Link to other repo]
[Replace with actual issue link, e.g., Fixes https://github.com/username/repo/issues/123]
Additional Notes
[Any additional context, concerns, or notes for reviewers]
Note
Low Risk
Documentation-only changes to public security and bug bounty pages; no application or auth logic.
Overview
Replaces the short vulnerability disclosure page with the full Bug Bounty Program: Scope and Policy document, so researchers get scope tiers, fixed rewards, rules of engagement, severity methodology, SLAs, safe harbor, and disclosure terms in one place instead of only a HackerOne embed.
The submission form moves into an Accordion under §2 and points at the current HackerOne program embed URL. Policy body is documented as a verbatim copy of the internal source of truth, with Mintlify-only tweaks (frontmatter, accordion, escaped
\$).security.mdx§2.3 is retitled from Vulnerability Disclosure to Bug Bounty Program, summarizes rewards/safe harbor at a high level, and links to the policy page so reward tables and commitments are not duplicated. Last Modified is updated to August 27, 2026.Reviewed by Cursor Bugbot for commit 1d1e847. Bugbot is set up for automated code reviews on this repo. Configure here.