Skip to content

Conversation

UlisesGascon
Copy link
Member

@UlisesGascon UlisesGascon commented Jul 17, 2025

The program is not yet public (login and team addition is required) https://yeswehack.com/business-units/sovereign-tech-fund/programs/express-js-bug-bounty-program

This will require the review from the @expressjs/security-triage and @expressjs/express-tc. Also we will need to wait for the feedback from STF and YesWeHack team (before merging) 👍

Related

@UlisesGascon UlisesGascon requested review from a team July 17, 2025 13:42
@UlisesGascon UlisesGascon self-assigned this Jul 17, 2025

### Bug bounty description

| Scope Type | Scope | Asset value |
Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note for myself: Check that the npm versions are correctly deprecated and aligned with the LTS plan. Only express was verified

Copy link
Member

@bjohansebas bjohansebas left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM


The scope of this program spans multiple npm packages maintained by the Express.js team across three GitHub organizations ([expressjs](https://github.com/expressjs), [pillarjs](https://github.com/pillarjs) and [jshttp](https://github.com/jshttp)). These repositories contain the core modules, middleware components, and foundational utilities that power the Express.js ecosystem.

This bug bounty program is paid for by the [Sovereign Tech Resilience program](https://www.sovereigntechfund.de/programs/bug-resilience).

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This URL redirects with 301 to https://www.sovereign.tech/programs/bug-resilience. Maybe we could use that instead


## Bug Bounty Program

The Express project participates in a paid bug bounty program funded by the [Sovereign Tech Resilience Program](https://www.sovereigntechfund.de/programs/bug-resilience) and hosted on YesWeHack.

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Same as above

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Time for a bounty program? Update Security Policies and Procedures

7 participants