Ross ROSS = Recommend OSS · open-source software intelligence for agents

disclose/bug-bounty-platforms resource

A community-powered collection of all known bug bounty platforms, vulnerability disclosure platforms, and crowdsourced security platforms currently active on the Internet. observed · 2026-08-28

github.com/disclose/bug-bounty-platforms · homepage · Python · CC0-1.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

76/100

  • Activity 97
  • Release rhythm 35
  • Longevity 100

Flags: no_releases

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 1866
  • days_rel: n/a
  • days_push: 22
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1101 stars · 216 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

A community-maintained, CC0-licensed catalog of every known bug bounty platform, vulnerability disclosure platform, and crowdsourced security platform active on the Internet, with structured metadata per platform. It is part of the disclose.io project and powers the browsable directory at disclose.io/platforms.

Use cases

  • find bug bounty platforms to run a program on
  • list of vulnerability disclosure platforms
  • where can I report a vulnerability to a government
  • compare crowdsourced security platforms with leaderboards
  • find web3 and AI security bounty platforms
  • research data on bug bounty ecosystem
  • find official channels to disclose a security bug

When to choose

  • you need an open, structured, regularly updated dataset of disclosure platforms
  • you want CC0 data you can freely reuse in tools or research
  • you need coverage of government VDPs and niche ecosystem platforms

When to avoid

  • you need a platform to actually host your bounty program rather than a directory of them
  • you need program-level scope details rather than platform-level info (see directory.disclose.io)
  • you need real-time program status guarantees

Facets

dataset · maturity active

security developer-tools documentation security awesome-lists developer-tools cli cross-platform bug-bounty vulnerability-disclosure crowdsourced-security curated-list open-data disclose-io safe-harbor web-server

4 sources

Member repositories

RepositoryRoleHealth v2
disclose/bug-bounty-platformsmain76

For agents

markdown · JSON · MCP: product_card(name="disclose/bug-bounty-platforms")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem