FAQs

Is this a bug bounty program?

No. This program focuses on recognition and ethical disclosure.

Yes. Both individuals and organisations may be listed.

Yes. Recognition by alias or handle is supported.

Public disclosure before coordinated remediation makes a report ineligible.

Projects aim to resolve issues within three months, in line with the Open VSX Security Policy.

The Open VSX Security Policy can be found here

Ready to contribute?

Help strengthen the Open VSX Registry through responsible security research.