pendulum-bug-bounty-program
3
In Scope
4
Out of Scope
In-Scope Assets (3)
| Asset | Category | Bounty | Quick Links | |
|---|---|---|---|---|
| https://github.com/pendulum-project/clock-steering | OPEN-SOURCE | Yes | - | |
| https://github.com/pendulum-project/ntpd-rs | OPEN-SOURCE | Yes | - | |
| https://github.com/pendulum-project/timestamped-socket | OPEN-SOURCE | Yes | - |
Out-of-Scope Assets (4)
| Asset | Category | Bounty | |
|---|---|---|---|
| Anything related to *.ntpd-rs.pendulum-project.org | OTHER | Yes | |
| Anything related to the CI pipeline or GitHub related hosting | OTHER | Yes | |
| Anything related to the NTPv5 and/or NTS Pool KE features (both disabled by default), unless it impacts other parts of the software | OTHER | Yes | |
| Known protocol limitations related to the NTP protocol | OTHER | Yes |
Scope Changes (25)
Feb 25, 2026
| Change | Asset | Category | Scope | Time |
|---|---|---|---|---|
| Added | anything related to the ci pipeline or github related hosting | OTHER | Out of Scope | 19:08 |
| Added | https://github.com/pendulum-project/ntpd-rs | CODE | In Scope | 19:08 |
| Added | https://github.com/pendulum-project/timestamped-socket | CODE | In Scope | 19:08 |
| Added | https://github.com/pendulum-project/clock-steering | CODE | In Scope | 19:08 |
| Added | known protocol limitations related to the ntp protocol | OTHER | Out of Scope | 19:08 |
| Added | anything related to the ntpv5 and/or nts pool ke features (both disabled by default), unless it impacts other parts of the software | OTHER | Out of Scope | 19:08 |
| Added | anything related to *.ntpd-rs.pendulum-project.org | WILDCARD | Out of Scope | 19:08 |
Feb 22, 2026
| Change | Asset | Category | Scope | Time |
|---|---|---|---|---|
| Added | https://github.com/pendulum-project/timestamped-socket | CODE | In Scope | 00:51 |
| Added | https://github.com/pendulum-project/clock-steering | CODE | In Scope | 00:51 |
| Added | known protocol limitations related to the ntp protocol | OTHER | Out of Scope | 00:51 |
| Added | anything related to the ntpv5 and/or nts pool ke features (both disabled by default), unless it impacts other parts of the software | OTHER | Out of Scope | 00:51 |
| Added | anything related to *.ntpd-rs.pendulum-project.org | WILDCARD | Out of Scope | 00:51 |
| Added | anything related to the ci pipeline or github related hosting | OTHER | Out of Scope | 00:51 |
| Added | https://github.com/pendulum-project/ntpd-rs | CODE | In Scope | 00:51 |
Feb 21, 2026
| Change | Asset | Category | Scope | Time |
|---|---|---|---|---|
| Removed | anything related to the ci pipeline or github related hosting | OTHER | Out of Scope | 21:40 |
| Removed | https://github.com/pendulum-project/clock-steering | OPEN-SOURCE | In Scope | 21:40 |
| Removed | known protocol limitations related to the ntp protocol | OTHER | Out of Scope | 21:40 |
| Removed | anything related to the ntpv5 and/or nts pool ke features (both disabled by default), unless it impacts other parts of the software | OTHER | Out of Scope | 21:40 |
| Removed | anything related to *.ntpd-rs.pendulum-project.org | OTHER | Out of Scope | 21:40 |
| Removed | https://github.com/pendulum-project/ntpd-rs | OPEN-SOURCE | In Scope | 21:40 |
| Removed | https://github.com/pendulum-project/timestamped-socket | OPEN-SOURCE | In Scope | 21:40 |
| Added | anything related to the ntpv5 and/or nts pool ke features (both disabled by default), unless it impacts other parts of the software | OTHER | Out of Scope | 00:33 |
| Added | anything related to *.ntpd-rs.pendulum-project.org | OTHER | Out of Scope | 00:33 |
| Added | anything related to the ci pipeline or github related hosting | OTHER | Out of Scope | 00:33 |
| Added | known protocol limitations related to the ntp protocol | OTHER | Out of Scope | 00:33 |