Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -1,11 +1,15 @@
---
date: 2026-01-21T12:00:00.000Z
date: 2026-02-19T12:00:00.000Z
category: announcements
title: New HackerOne Signal Requirement for Vulnerability Reports
layout: blog-post
author: The Node.js Project
---

**UPDATE 2026-02-19**: New researchers without signal can no longer submit reports through HackerOne. If you are a new researcher and would like to report a potential vulnerability, please reach out to the [Node.js security release stewards](https://github.com/nodejs/node?tab=readme-ov-file#security-release-stewards) through the [OpenJS Foundation Slack](https://slack-invite.openjsf.org/).

---

We have updated our [HackerOne program](https://hackerone.com/nodejs) to require a **Signal of 1.0 or
higher** to submit vulnerability reports to the Node.js project.

Expand Down
Loading