Subject: Inquiry Regarding Bug Bounty Program Rewards and Policies #13141

Closed
opened 2026-02-21 19:10:44 -05:00 by yindo · 1 comment
Owner

Originally created by @Swapnil-Ade on GitHub (Apr 19, 2025).

Originally assigned to: @crazywoola on GitHub.

Self Checks

  • This is only for bug report, if you would like to ask a question, please head to Discussions.
  • I have searched for existing issues search for existing issues, including closed ones.
  • I confirm that I am using English to submit this report (我已阅读并同意 Language Policy).
  • [FOR CHINESE USERS] 请务必使用英文提交 Issue,否则会被关闭。谢谢!:)
  • Please do not modify this template :) and fill in all the required fields.

Dify version

Cloud or Self Hosted

Self Hosted (Docker)

Steps to reproduce

Dear security team,

I hope this email finds you well.

I am reaching out to inquire about your bug bounty program. Specifically, I would like to know if your program offers rewards or compensation for valid bug submissions. Additionally, it would be helpful if you could share details about your policies, including the scope of the program and the process for reporting vulnerabilities.

I am committed to responsible disclosure and ensuring the security of your systems, and I look forward to understanding how I can contribute effectively.

Thank you for your time and support. I look forward to your response.

Best regards

✔️ Expected Behavior

Dear security team,

I hope this email finds you well.

I am reaching out to inquire about your bug bounty program. Specifically, I would like to know if your program offers rewards or compensation for valid bug submissions. Additionally, it would be helpful if you could share details about your policies, including the scope of the program and the process for reporting vulnerabilities.

I am committed to responsible disclosure and ensuring the security of your systems, and I look forward to understanding how I can contribute effectively.

Thank you for your time and support. I look forward to your response.

Best regards

Actual Behavior

Dear security team,

I hope this email finds you well.

I am reaching out to inquire about your bug bounty program. Specifically, I would like to know if your program offers rewards or compensation for valid bug submissions. Additionally, it would be helpful if you could share details about your policies, including the scope of the program and the process for reporting vulnerabilities.

I am committed to responsible disclosure and ensuring the security of your systems, and I look forward to understanding how I can contribute effectively.

Thank you for your time and support. I look forward to your response.

Best regards

Originally created by @Swapnil-Ade on GitHub (Apr 19, 2025). Originally assigned to: @crazywoola on GitHub. ### Self Checks - [x] This is only for bug report, if you would like to ask a question, please head to [Discussions](https://github.com/langgenius/dify/discussions/categories/general). - [x] I have searched for existing issues [search for existing issues](https://github.com/langgenius/dify/issues), including closed ones. - [x] I confirm that I am using English to submit this report (我已阅读并同意 [Language Policy](https://github.com/langgenius/dify/issues/1542)). - [x] [FOR CHINESE USERS] 请务必使用英文提交 Issue,否则会被关闭。谢谢!:) - [x] Please do not modify this template :) and fill in all the required fields. ### Dify version - ### Cloud or Self Hosted Self Hosted (Docker) ### Steps to reproduce Dear security team, I hope this email finds you well. I am reaching out to inquire about your bug bounty program. Specifically, I would like to know if your program offers rewards or compensation for valid bug submissions. Additionally, it would be helpful if you could share details about your policies, including the scope of the program and the process for reporting vulnerabilities. I am committed to responsible disclosure and ensuring the security of your systems, and I look forward to understanding how I can contribute effectively. Thank you for your time and support. I look forward to your response. Best regards ### ✔️ Expected Behavior Dear security team, I hope this email finds you well. I am reaching out to inquire about your bug bounty program. Specifically, I would like to know if your program offers rewards or compensation for valid bug submissions. Additionally, it would be helpful if you could share details about your policies, including the scope of the program and the process for reporting vulnerabilities. I am committed to responsible disclosure and ensuring the security of your systems, and I look forward to understanding how I can contribute effectively. Thank you for your time and support. I look forward to your response. Best regards ### ❌ Actual Behavior Dear security team, I hope this email finds you well. I am reaching out to inquire about your bug bounty program. Specifically, I would like to know if your program offers rewards or compensation for valid bug submissions. Additionally, it would be helpful if you could share details about your policies, including the scope of the program and the process for reporting vulnerabilities. I am committed to responsible disclosure and ensuring the security of your systems, and I look forward to understanding how I can contribute effectively. Thank you for your time and support. I look forward to your response. Best regards
yindo closed this issue 2026-02-21 19:10:44 -05:00
Author
Owner

@dosubot[bot] commented on GitHub (May 21, 2025):

Hi, @anonghost007. I'm Dosu, and I'm helping the Dify team manage their backlog. I'm marking this issue as stale.

Issue Summary:

  • You inquired about the bug bounty program for the Dify repository.
  • Specifically, you asked about rewards, policies, scope, and the process for reporting vulnerabilities.
  • You emphasized your commitment to responsible disclosure.
  • There have been no responses or further activity on this issue.

Next Steps:

  • Please let us know if this issue is still relevant to the latest version of the Dify repository by commenting here.
  • If there is no further activity, this issue will be automatically closed in 15 days.

Thank you for your understanding and contribution!

@dosubot[bot] commented on GitHub (May 21, 2025): Hi, @anonghost007. I'm [Dosu](https://dosu.dev), and I'm helping the Dify team manage their backlog. I'm marking this issue as stale. **Issue Summary:** - You inquired about the bug bounty program for the Dify repository. - Specifically, you asked about rewards, policies, scope, and the process for reporting vulnerabilities. - You emphasized your commitment to responsible disclosure. - There have been no responses or further activity on this issue. **Next Steps:** - Please let us know if this issue is still relevant to the latest version of the Dify repository by commenting here. - If there is no further activity, this issue will be automatically closed in 15 days. Thank you for your understanding and contribution!
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#13141