Vulnerability Disclosure Program (VDP)

VDPs are meant for responsibly reporting vulnerabilities you encounter — not for actively hunting for fame or reputation. Even if you're just starting out, consider focusing on rewarded bug bounty programs instead.

rails

HackerOneView on HackerOne
RawAI Enhanced
1
In Scope
1
Out of Scope
In-Scope Assets (1)
AssetCategoryBountyQuick Links
https://github.com/rails/railsCODENo-
Out-of-Scope Assets (1)
AssetCategoryBounty
*.rubyonrails.orgWILDCARDNo
Scope Changes (11)
Apr 1, 2026
ChangeAssetCategoryScopeTime
Removedhttps://github.com/rails/railsCODEIn Scope21:21
Mar 26, 2026
ChangeAssetCategoryScopeTime
Addedhttps://github.com/rails/railsCODEIn Scope17:21
Addedhttps://github.com/rails/railsCODEIn Scope17:21
Added*.rubyonrails.orgWILDCARDOut of Scope17:21
Added*.rubyonrails.orgWILDCARDOut of Scope17:21
Program Removed16:08
Feb 25, 2026
ChangeAssetCategoryScopeTime
Added*.rubyonrails.orgWILDCARDOut of Scope19:08
Addedhttps://github.com/rails/railsCODEIn Scope19:08
Feb 22, 2026
ChangeAssetCategoryScopeTime
Addedhttps://github.com/rails/railsCODEIn Scope00:39
Added*.rubyonrails.orgWILDCARDOut of Scope00:39
Feb 21, 2026
ChangeAssetCategoryScopeTime
Removedhttps://github.com/rails/railsCODEIn Scope21:38