GitHub Copilot · Vulnerability Disclosure

Github Copilot Vulnerability Disclosure

Vulnerability disclosure

GitHub Copilot runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

AgentsAIArtificial IntelligenceCode GenerationCode ReviewCoding AgentCustom InstructionsDeveloper ToolsExtensionsIDEMachine LearningMCPMetricsModel Context ProtocolProductivity
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
https://hackerone.com/github

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-06-20'
method: searched
probe: true
source: >-
  https://github.com/.well-known/security.txt (RFC 9116, fetched 200) and
  https://bounty.github.com. GitHub runs a public bug bounty program on
  HackerOne.
policy:
  - https://bounty.github.com
contact:
  - https://hackerone.com/github
acknowledgments:
  - https://hackerone.com/github/hacktivity
bug_bounty:
  platform: HackerOne
  url: https://hackerone.com/github
  program_page: https://bounty.github.com
preferred_languages: en
security_txt_expires: '2026-08-15T21:29:55Z'
evidence:
  - {source: well-known/github-copilot-security.txt, kind: security.txt, host: github.com}
  - {source: https://bounty.github.com, kind: bug-bounty-policy}
  - {source: https://hackerone.com/github, kind: hackerone-program}
notes: >-
  security.txt is published org-wide at github.com and covers GitHub Copilot.
  The canonical Contact is the HackerOne program; Policy points at
  bounty.github.com (the GitHub Bug Bounty program page).