# projectdiscovery/public-bugbounty-programs

Community curated list of public bug bounty and responsible disclosure programs.

Repository: https://github.com/projectdiscovery/public-bugbounty-programs
Canonical: https://ross.abutalabs.com/products/public-bugbounty-programs
Homepage: https://chaos.projectdiscovery.io
Language: Go
License: MIT
License Family: permissive
Topics: chaos, bugbounty, reconnaissance, hacktoberfest, bugbounty-program
Last push: 2026-08-17T07:03:33+00:00

## Health v2 (maintenance only)
Score: 76/100 (v2, computed 2026-09-03T02:39:23.370411+00:00)
- activity 98, release rhythm 35, longevity 100
- inputs: {"age_days": 2310, "days_push": 16, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1341, forks 391 (observed 2026-08-28T04:04:26.159414+00:00)

## What it is
A community-curated dataset of public bug bounty and responsible disclosure programs, maintained as YAML with a JSON schema and distributed as JSON. It powers the Chaos platform by ProjectDiscovery, which offers reconnaissance data over these program domains.

## Use cases
- find public bug bounty programs to hack on
- get a list of in-scope domains for responsible disclosure
- feed bug bounty targets into recon tooling
- download bug bounty program data as JSON or YAML
- contribute a new bug bounty program to a curated list

## When to choose
- you need a machine-readable, community-maintained list of bug bounty program domains
- you use Chaos or other ProjectDiscovery recon tools and want program targets
- you want to contribute or track public responsible disclosure programs

## When to avoid
- you need private or paid bounty platform data with full program policies
- you need real-time subdomain enumeration rather than a static target list
- you need vulnerability scanning itself rather than target data

## Facets
- artifact type: dataset
- maturity: active
- function: security, osint, data-generation
- domain: security, penetration-testing, crawlers
- platform: cli
- tags: bug-bounty, responsible-disclosure, reconnaissance, chaos, yaml-dataset, community-curated, web-server

## Member repositories
- projectdiscovery/public-bugbounty-programs (main) score 76

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:26.159414+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:43:45.802594+00:00, confidence not recorded.
  - readme: https://github.com/projectdiscovery/public-bugbounty-programs (fetched 2026-08-28T04:04:26.159414+00:00, sha c17c2b101eca)
  - homepage: https://chaos.projectdiscovery.io (fetched 2026-08-29T12:02:39.707737+00:00, sha a48c3b0ab6f6)
  - site_page: https://chaos.projectdiscovery.io/docs (fetched 2026-08-29T12:02:39.716594+00:00, sha a70ba823e9e0)
  - site_page: https://projectdiscovery.io/about-us (fetched 2026-08-29T12:02:39.718359+00:00, sha a550ca3a1316)
- Data as of 2026-08-30T08:39:29.467469+00:00.
