Vulnerability Disclosure Program (VDP)

VDPs are meant for responsibly reporting vulnerabilities you encounter — not for actively hunting for fame or reputation. Even if you're just starting out, consider focusing on rewarded bug bounty programs instead.

rubygems

HackerOneView on HackerOne
RawAI Enhanced
4
In Scope
9
Out of Scope
In-Scope Assets (4)
AssetCategoryBountyQuick Links
Malicious or compromised gemOTHERNo-
https://github.com/rubygems/rubygemsCODENo-
rubygems.orgURLNo
shipit.rubygems.orgURLNo
Out-of-Scope Assets (9)
Scope Changes (34)
Mar 30, 2026
ChangeAssetCategoryScopeTime
Removedhttps://github.com/rubygems/rubygemsCODEIn Scope01:21
Feb 25, 2026
ChangeAssetCategoryScopeTime
Addedhttps://github.com/rubygems/rubygemsCODEIn Scope19:09
Addedsupport.rubygems.orgURLOut of Scope19:09
Addeduptime.rubygems.orgURLOut of Scope19:09
Addedblog.rubygems.orgURLOut of Scope19:09
Addedstatus.rubygems.orgURLOut of Scope19:09
Addedrubygems.orgURLIn Scope19:09
Addedmalicious or compromised gemOTHERIn Scope19:09
Addedshipit.rubygems.orgURLIn Scope19:09
Addedhelp.rubygems.orgURLOut of Scope19:09
Addedhttps://s3-us-west-2.amazonaws.com/rubygems-dumpsURLOut of Scope19:09
Addedhttp://rubygems.org/namesURLOut of Scope19:09
Addedguide.rubygems.orgURLOut of Scope19:09
Addedstats.rubygems.orgURLOut of Scope19:09
Feb 24, 2026
ChangeAssetCategoryScopeTime
Removedrubygems.orgURLIn Scope10:15
Removedgem server commandOTHEROut of Scope10:15
Feb 22, 2026
ChangeAssetCategoryScopeTime
Addedsupport.rubygems.orgURLOut of Scope00:40
Addedguide.rubygems.orgURLOut of Scope00:40
Addedrubygems.orgURLIn Scope00:40
Addedhttps://s3-us-west-2.amazonaws.com/rubygems-dumpsURLOut of Scope00:40
Addedhttp://rubygems.org/namesURLOut of Scope00:40
Addedgem server commandOTHEROut of Scope00:40
Addeduptime.rubygems.orgURLOut of Scope00:40
Addedblog.rubygems.orgURLOut of Scope00:40
Addedstats.rubygems.orgURLOut of Scope00:40
Addedstatus.rubygems.orgURLOut of Scope00:40
Addedhttps://github.com/rubygems/rubygemsURLIn Scope00:40
Addedmalicious or compromised gemOTHERIn Scope00:40
Addedshipit.rubygems.orgURLIn Scope00:40
Addedhelp.rubygems.orgURLOut of Scope00:40
Feb 21, 2026
ChangeAssetCategoryScopeTime
Removedrubygems.orgURLIn Scope21:38
Removedhttps://github.com/rubygems/rubygemsCODEIn Scope21:38
Addedmalicious or compromised gemOTHERIn Scope19:11
Addedshipit.rubygems.orgURLIn Scope19:11