# reddelexc/hackerone-reports

Top disclosed reports from HackerOne

Repository: https://github.com/reddelexc/hackerone-reports
Canonical: https://ross.abutalabs.com/products/hackerone-reports
Language: Python
License Family: other
Topics: writeups, hackerone, bugbounty, reports, xss, xxe, sql-injection, csrf, idor, rce, ssrf, security
Last push: 2026-08-17T03:50:41+00:00

## Health v2 (maintenance only)
Score: 76/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 98, release rhythm 35, longevity 100
- inputs: {"age_days": 2693, "days_push": 16, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 6481, forks 1139 (observed 2026-08-28T04:09:43.745620+00:00)

## What it is
A curated dataset of top disclosed HackerOne bug bounty reports, ranked by upvotes, bounties, bug type, and program, with raw data in data.csv and Python scripts to fetch and update it. It also publishes browsable markdown tops and a live GitHub Pages site.

## Use cases
- find top disclosed bug bounty reports to learn from
- study real-world XSS and SQL injection examples
- get a CSV dataset of HackerOne disclosures for analysis
- research which bug types earn the highest bounties
- learn penetration testing from real reports
- browse top reports for a specific bug bounty program

## When to choose
- you want curated, ranked real-world vulnerability writeups for learning
- you need structured disclosed-report data for research or analysis
- you want per-bug-type or per-program report collections

## When to avoid
- you need a vulnerability scanner or exploitation tool
- you want private or non-disclosed bug bounty data
- you need an actively maintained security library with a license

## Facets
- artifact type: dataset
- maturity: active
- function: security, web-scraping, data-science
- domain: security, penetration-testing, education
- platform: python, cli
- tags: bug-bounty, hackerone, writeups, vulnerability-research, csv-dataset, learning-resource, web-server

## Member repositories
- reddelexc/hackerone-reports (main) score 76

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:09:43.745620+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T17:44:32.572526+00:00, confidence not recorded.
  - readme: https://github.com/reddelexc/hackerone-reports (fetched 2026-08-28T04:09:43.745620+00:00, sha 252db90df1f7)
- Data as of 2026-08-30T08:39:29.467469+00:00.
