Early access: this site has moved to bugrater.com.
NR Unrated
GitLab
GitLab HackerOne
3 more reviews needed for a grade
Write a review Claim this company profile

Work at GitLab? Claim it to respond to reviews as the verified owner.

Found a vulnerability?

If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.

Ask BugRater to submit it

Private. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.

Program metrics HackerOne · published

HackerOne’s own figures for this program, read from its public page, not reported by researchers and not part of the BugRater grade. Captured 22 Sep 2026.

What it pays, by severity

Critical $4,501 avg 107 reports firm
High $11,354 avg 456 reports firm
Medium $1,353 avg 982 reports firm
Low $649 avg 580 reports firm

$7,197,887 paid to researchers in total, $332,422 of it in the last 90 days. Lifetime figure as HackerOne prints it: evidence this program has paid, not a promise about any one report.

Intake & responsiveness · last 90 days

Reports received
4,177
in 90 days
Resolved
2,248
all time, last one 6 days ago
Participants
988
hunters engaged
Response efficiency
71%
below its own targets, HackerOne’s figure
SLA misses
0
targets missed
Reports received · day by day, last 15 days 3,382–4,177
25 Aug 4,177 reports 22 Sep

Response targets it sets itself

First response
1 day
Triage
5 days
Bounty
30 days
Resolution
30 days

A target the program declared, not a measurement of it being met.

Getting in the door

Open to submit. Nothing HackerOne publishes stands between a hunter and a first report here.

Over 33 days (18 snapshots): intake up 960 reports; response efficiency down 6 points; 90-day payout down $51,974.

See how this programme’s report load compares to others →

Reviews

0 published

No reviews yet.

Be the first to review

Who this program credits

1,018 credited

Researchers HackerOne shows on this program’s public thanks list, best position first. “Recognised” is how many of a hunter’s submissions the program accepted; the ratio is their signal here, not our judgement of them.

# Researcher Reputation Recognised / submitted
1 joaxcar 6,932 203 / 258 79%
2 ashish_r_padelkar 3,175 183 / 317 58%
3 yvvdwf 3,073 84 / 110 76%
4 xanbanx 3,015 133 / 175 76%
5 mateuszek 2,327 89 / 354 25%
6 ngalog 1,884 85 / 116 73%
7 0xn3va 1,778 48 / 69 70%
8 pwnie 1,702 65 / 540 12%
9 albatraoz 1,303 56 / 80 70%
10 taraszelyk 1,197 26 / 27 96%
11 vakzz 1,152 31 / 38 82%
12 anhiu102 1,079 39 / 47 83%
13 saltyyolk 1,028 25 / 26 96%
14 jobert 946 48 / 52 92%
15 theluci 762 31 / 89 35%
16 fransrosen 755 20 / 21 95%
17 rogerace 750 26 / 124 21%
18 js_noob 689 34 / 96 35%
19 shells3c 668 36 / 74 49%
20 ledz1996 654 17 / 25 68%
21 d0xing 645 31 / 53 58%
22 vaib25vicky 616 34 / 73 47%
23 rpadovani 607 25 / 36 69%
24 st4nly0n 604 23 / 53 43%
25 sim4n6 569 19 / 73 26%

Showing the top 25 of 1,018 credited on HackerOne.

Program profile HackerOne · imported

Facts published by HackerOne on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 16 Sep 2026.

A single application for the entire software development lifecycle.

Responsiveness
72% HackerOne’s figure
Swag
No
Currency
USD
Submissions
Open
Launched
Feb 2016
Scope entries
63 HackerOne’s count

Scope

59 assets
AssetTypeEligibilityMax severity
*.gitlab.org WILDCARD ✓ bounty Medium
advisories.gitlab.com URL ✓ bounty Medium
customers.gitlab.com URL ✓ bounty Critical
design.gitlab.com URL ✓ bounty Medium
GitLab for Jira Cloud OTHER ✓ bounty Medium
Show all 59 assets
AssetTypeEligibilityMax severity
GitLab for Jira Cloud Plugin OTHER ✓ bounty Critical
gitlab.com URL ✓ bounty Critical
https://gitlab.com/gitlab-org/gitaly SOURCE CODE ✓ bounty Critical
https://gitlab.com/gitlab-org/gitlab SOURCE CODE ✓ bounty Critical
https://gitlab.com/gitlab-org/gitlab-pages SOURCE CODE ✓ bounty Critical
https://gitlab.com/gitlab-org/gitlab-runner SOURCE CODE ✓ bounty Critical
https://gitlab.com/gitlab-org/gitlab-shell SOURCE CODE ✓ bounty Critical
https://gitlab.com/gitlab-org/gitlab-vscode-extension SOURCE CODE ✓ bounty Critical
https://gitlab.com/gitlab-org/gitlab-workhorse SOURCE CODE ✓ bounty Critical
https://gitlab.com/gitlab-org/opstrace/ SOURCE CODE ✓ bounty Critical
license.gitlab.com URL ✓ bounty Critical
Other non-production infrastructure OTHER ✓ bounty Medium
registry.gitlab.com URL ✓ bounty Critical
Static websites OTHER ✓ bounty Medium
Your Own GitLab Instance OTHER ✓ bounty Critical
*.gitlab-private.org WILDCARD out None
*.gitlab.cn WILDCARD out None
*.gitlab.net URL out None
*.gitlap.com URL out None
*.gitter.im WILDCARD out None
*.runway.gitlab.net WILDCARD out None
*.service-now.com WILDCARD out None
about.gitlab.com URL out None
alerts.gitlab.com URL out None
api.gitter.im URL out None
aptly.gitlab.com URL out None
beta.gitter.im URL out None
blog.gitter.im URL out None
dashboards.gitlab.com URL out None
docs.gitlab.com URL out None
federal-support.gitlab.com URL out None
files.gitter.im URL out None
forum.gitlab.com URL out None
gitlab.biterg.io URL out None
gitlab.net URL out None
gitlabdemo.cloud URL out None
gitlabsandbox.net URL out None
gitlabtraining.cloud URL out None
gitlap.com URL out None
https://gitlab.com/gitlab-org/cli/ SOURCE CODE out None
https://gitlab.com/gitlab-org/opstrace/opstrace SOURCE CODE out None
https://gitlab.com/gitlab-org/opstrace/opstrace-ui SOURCE CODE out None
ir.gitlab.com URL out None
levelup.gitlab.com URL out None
next.gitter.im URL out None
packages.gitlab.com URL out None
partners.gitlab.com URL out None
shop.gitlab.com URL out None
status.gitlab.com URL out None
support.gitlab.com URL out None
translate.gitlab.com URL out None
update.gitter.im URL out None
us-federal-gitlab.com URL out None
ws*.gitter.im WILDCARD out None

HackerOne lists 63 scope entries; its public listing groups many assets under one label, so identical entries are shown once.