Scope Updates

Recent changes to bug bounty program scopes.

ChangeAssetCategoryScopeProgramPlatformTime
Addeddeezer-blog.comOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addeddeezercommunity.comOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedsupport.deezer.comOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedcdn-content.deezer.comOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedcdn-files.deezer.comOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedpartners.deezer.comOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addeddevelopers.deezer.comOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedall domains or subdomains not listed in the above list of 'scopes'OTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedjenkins instances hosted by users are not in scopeOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedjenkins project infrastructure (the one hosted by the project) is not in scopeOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedjenkins installers are not in scopeOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedany components/plugins not explicitly included are not in scope (e.g. forks, libraries or packages)OTHEROut of ScopeYesWeHack2026-02-21 00:33
Addeddocker images are not in scope for this programOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedeverything from https://www.jenkins.io/security/reporting/#non-issues, and in addition the following itemsOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedall domains or subdomains not listed in the above list of 'scopes'OTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedall 3rd parties are out of scopeOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedall domains not listed in-scopeOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedthird-party companies that perform business transactions for spaceliftOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addeddata breaches or credential dumpsOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedattacks against any account other than the specified target accountsOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedany communication with spacelift colleaguesOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedany other spacelift assets not specifically listed as in-scopeOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedcontact form (especially hubspot ones)OTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedbypasses of user or api key creation limits (including via race conditions or business logic issues)OTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedsession keeps using old user group permissions if user group permissions are changed during a given session's lifespanOTHEROut of ScopeYesWeHack2026-02-21 00:33