Vulnerability Disclosure Program (VDP)
VDPs are meant for responsibly reporting vulnerabilities you encounter — not for actively hunting for fame or reputation. Even if you're just starting out, consider focusing on rewarded bug bounty programs instead.
solidus
2
In Scope
1
Out of Scope
In-Scope Assets (2)
| Asset | Category | Bounty | Quick Links | |
|---|---|---|---|---|
| https://github.com/solidusio/solidus | CODE | No | - | |
| https://github.com/solidusio/solidus_auth_devise | CODE | No | - |
Out-of-Scope Assets (1)
| Asset | Category | Bounty | |
|---|---|---|---|
| *solidus.io | WILDCARD | No |
Scope Changes (6)
Aug 14, 2026
| Change | Asset | Category | Scope | Time |
|---|---|---|---|---|
| Added | https://github.com/solidusio/solidus | CODE | In Scope | 12:50 |
| Added | https://github.com/solidusio/solidus_auth_devise | CODE | In Scope | 12:50 |
| Added | *solidus.io | WILDCARD | Out of Scope | 12:50 |
| Added | https://github.com/solidusio/solidus_auth_devise | CODE | In Scope | 12:50 |
| Added | *solidus.io | WILDCARD | Out of Scope | 12:50 |
| Added | https://github.com/solidusio/solidus | CODE | In Scope | 12:50 |