Skip to content

It's hard to search for issues labeled as bounty across an entire organization #287

@mskiptr

Description

@mskiptr

Hello! I was looking into your bounty program and while it is definitely quite interesting, I feel it could be documented a bit better. More specifically, the overview at https://3mdeb.com/bug-bounty/ says

Browse our repositories on GitHub, such as the ones available in the Dasharo and Zarhus organizations, and look for issues tagged with “bounty” and a category tag (e.g., “bounty-easy”).

At the same time, the vast majority of those seem to be located in just the Dasharo/dasharo-issues repository, with a few in Dasharo/open-source-firmware-validation instead. (And btw, when searching based on labels, due to a typo, a slightly different set of issues is returned.) I couldn't find any of those issues in the Zarhus org tho.

Additionally, the readme in that Dasharo/dasharo-issues repo is quite relevant here, so the main website should probably link to that. The link in the opposite direction is already there tho.

Finally this is a bit off-topic for this issue, but: While trying to learn more about your bounty program I ended up spotting a few other areas for improvement. See the commit messages and diffs over at mskiptr/3mdeb-website:wip-fixes-2025-12-05. Most of those commits should serve as a good starting point. Also, this line sounds like it's missing half of a sentence there.

Metadata

Metadata

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions