From 0a5749c91392dc01fb63f0f5597cf3f54620ddc0 Mon Sep 17 00:00:00 2001 From: Iain Date: Thu, 13 Aug 2026 19:42:00 +0100 Subject: [PATCH 1/2] Add program: Socket --- independent-programs.yml | 32 ++++++++++++++++++++++++++++++++ 1 file changed, 32 insertions(+) diff --git a/independent-programs.yml b/independent-programs.yml index d473569..d595620 100644 --- a/independent-programs.yml +++ b/independent-programs.yml @@ -1735,6 +1735,38 @@ companies: - '*.snapdeploy.dev' response_sla_days: 7 +- company: Socket + url: https://socket.dev/security/disclosure + contact: mailto:security@socket.dev + rewards: + - '*bounty' + program_type: bounty + status: active + safe_harbor: full + allows_disclosure: true + preferred_languages: English + description: Socket publishes a bounty schedule as a guide to expectations, roughly $50-100 for a minor issue with little risk, $500-1000 for a real problem that puts users at risk, and $1000+ for a really bad one. Reports go to security@socket.dev and are acknowledged within five business days, with critical issues aimed to be resolved within ten. Socket is generally happy to publicly disclose a report two weeks after shipping the release that contains the fix. + excluded_methods: + - dos + - social_engineering + - phishing + - physical_access + scope: + - target: socket.dev + type: web + - target: '*.socket.dev' + type: web + - target: socketusercontent.com + type: web + - target: '*.socketusercontent.com' + type: web + out_of_scope: + - CNAME subdomains such as feedback.socket.dev + - Spamming + min_payout: 50 + currency: USD + response_sla_days: 5 + - company: Soldera url: https://www.soldera.org/terms/vdp contact: mailto:security@soldera.org From 8f8524e199cfe302f14ddbfa47d67cd9146ca4d0 Mon Sep 17 00:00:00 2001 From: Iain Date: Thu, 13 Aug 2026 19:42:01 +0100 Subject: [PATCH 2/2] Add program: Tiger Data --- independent-programs.yml | 38 ++++++++++++++++++++++++++++++++++++++ 1 file changed, 38 insertions(+) diff --git a/independent-programs.yml b/independent-programs.yml index d595620..f6d47ee 100644 --- a/independent-programs.yml +++ b/independent-programs.yml @@ -1914,6 +1914,44 @@ companies: - target: TI product software and documentation type: other +- company: Tiger Data + url: https://www.tigerdata.com/security/vulnerability-disclosure + contact: mailto:security@tigerdata.com + rewards: + - '*recognition' + program_type: vdp + status: active + safe_harbor: full + preferred_languages: English + pgp_key: https://www.tigerdata.com/.well-known/security-key.txt + description: Timescale, Inc., trading as Tiger Data, runs a disclosure-only programme with no monetary rewards, offering credit in security advisories and a place in a researcher hall of fame instead. Reports go to security@tigerdata.com, must be in English, must demonstrate clear security impact, and only the latest released versions of its products are considered. Research conducted in line with the policy is authorised, and Tiger Data commits to no civil action and no complaint to law enforcement. + excluded_methods: + - dos + - social_engineering + - phishing + - physical_access + - automated_scanning + out_of_scope: + - SSL/TLS best practices + - Lack of rate limiting on non-sensitive endpoints, and brute force + - Open ports that do not lead directly to a vulnerability + - Missing HTTP security headers + - Descriptive error messages such as stack traces + - Missing cookie flags on non-sensitive cookies + - Logout CSRF + - OPTIONS/TRACE HTTP methods enabled + - Internal IP disclosure + - Presence or absence of SPF/DMARC records + - Clickjacking with no practical security impact + - Autocomplete or save password functionality being available + - Login or forgot password brute force, and account lockout not enforced + - Self XSS + - Functional, UI and UX bugs, and spelling mistakes + - Vulnerabilities that require extensive social engineering + - Third-party applications or services + - Issues only affecting users of outdated or unpatched browsers and platforms + - Vulnerabilities already known to Tiger Data or publicly disclosed + - company: TMG Security url: https://tmgsec.com/bug-bounty/ contact: mailto:security@tmgsec.com