A Deep Dive into How Open-Source Project Maintainers Review and Resolve Bug Bounty Reports
Jessy Ayala, Steven Ngo, Joshua Garcia
Abstract
Researchers have investigated the bug bounty ecosystem from the lens of platforms, programs, and bug hunters. Understanding the perspectives of bug bounty report reviewers, especially those who historically lack a security background and little to no funding for bug hunters, is currently under-studied. In this paper, we primarily investigate the perspective of open-source software (OSS) maintainers who have used huntr, a bug bounty platform that pays bounties to bug hunters who find security bugs in GitHub projects and have had valid vulnerabilities patched as a result. We address this area by conducting three studies: identifying characteristics through a listing survey , their ranked importance with Likert-scale survey data , and conducting semi-structured interviews to dive deeper into real-world experiences . As a result, we categorize 40 identified characteristics into benefits, challenges, helpful features, and wanted features. We find that private disclosure and project visibility are the most important benefits, while hunters focused on money or CVEs and pressure to review are the most challenging to overcome. Surprisingly, lack of communication with bug hunters is the least challenging, and CVE creation support is the second-least helpful feature for OSS maintainers when reviewing bug bounty reports. We present recommendations to make the bug bounty review process more accommodating to open-source maintainers and identify areas for future work.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f626e4f3-4b0b-4a65-8d84-3f7660f7fe29Cited by top-tier papers3
- Credible Threat Detection? Measuring Contribution Dynamics and Quality Control in a Crowdsourced Threat Detection EcosystemApurva Virkud, Gang Wang, Adam BatesUSENIX Security 2026 · 1 citation
- Responsible Disclosure is a Two-Way Street: Empirically Measuring the Responsible Disclosure Contract in the Firmware EcosystemHui Jun Tay, Souradip Nath, Arvind S. Raj, Abhay Bhat et al.S&P 2026
- A Mixed-Methods Study of Open-Source Software Maintainers On Vulnerability Management and Platform Security FeaturesJessy Ayala, Yu-Jye Tung, Joshua GarciaUSENIX Security 2025
Builds on6
- Hackers vs. Testers: A Comparison of Software Vulnerability Discovery ProcessesDaniel Votipka, Rock Stevens, Elissa M. Redmiles, Jeremy Hu et al.S&P 2018 · 151 citations
- Committed to Trust: A Qualitative Study on Security & Trust in Open Source Software ProjectsDominik Wermke, Noah Wöhler, Jan H. Klemmer, Marcel Fourné et al.S&P 2022 · 54 citations
- Leaving My Fingerprints: Motivations and Challenges of Contributing to OSS for Social GoodYu Huang, Denae Ford, Thomas ZimmermannICSE 2021 · 36 citations
- Understanding skills for OSS communities on GitHubJenny T. Liang, Thomas Zimmermann, Denae FordFSE 2022 · 31 citations
- The Benefits of Vulnerability Discovery and Bug Bounty Programs: Case Studies of Chromium and FirefoxSoodeh Atefi, Amutheezan Sivagnanam, Afiya Ayman, Jens Grossklags et al.WWW 2023 · 13 citations
Related papers
- Bug Hunters' Perspectives on the Challenges and Benefits of the Bug Bounty EcosystemOmer Akgul, Taha Eghtesad, Amit Elazari, Omprakash Gnawali et al.USENIX Security 2023
- Between Risk, Recognition, and Necessity: How Open-Source Project Maintainers Perceive and Navigate CVEs Through Reporting and Resolving VulnerabilitiesJessy Ayala, Steven Ngo, Joshua GarciaCCS 2026
- Study Club, Labor Union or Start-Up? Characterizing Teams and Collaboration in the Bug Bounty EcosystemYangheran Piao, Temima Hrle, Daniel W. Woods, Ross AndersonS&P 2025
- Vision: Identifying Affected Library Versions for Open Source Software VulnerabilitiesSusheng Wu, Ruisi Wang, Kaifeng Huang, Yiheng Cao et al.ASE 2024 · 1 citation
- Tracking patches for open source software vulnerabilitiesCongying Xu, Bihuan Chen, Chenhao Lu, Kaifeng Huang et al.FSE 2022 · 34 citations
