Vulnerability Disclosure Program (VDP)

VDPs are meant for responsibly reporting vulnerabilities you encounter — not for actively hunting for fame or reputation. Even if you're just starting out, consider focusing on rewarded bug bounty programs instead.

solidus

HackerOneView on HackerOne
RawAI Enhanced
2
In Scope
1
Out of Scope
In-Scope Assets (2)
AssetCategoryBountyQuick Links
https://github.com/solidusio/solidusCODENo-
https://github.com/solidusio/solidus_auth_deviseCODENo-
Out-of-Scope Assets (1)
AssetCategoryBounty
*solidus.ioWILDCARDNo
Scope Changes (6)
Aug 14, 2026
ChangeAssetCategoryScopeTime
Addedhttps://github.com/solidusio/solidusCODEIn Scope12:50
Addedhttps://github.com/solidusio/solidus_auth_deviseCODEIn Scope12:50
Added*solidus.ioWILDCARDOut of Scope12:50
Addedhttps://github.com/solidusio/solidus_auth_deviseCODEIn Scope12:50
Added*solidus.ioWILDCARDOut of Scope12:50
Addedhttps://github.com/solidusio/solidusCODEIn Scope12:50