跳到主要内容
ArcBlock Community

Updates to Bug Bounty Program Evaluation Criteria

wangshijun
公告

Dear Community Members,

Since the beginning of this year, we have been conducting our Bug Bounty Program to enhance the reliability and security of our platform, relying on valuable post from our users. We have received diverse post ranging from spelling errors and copywriting issues on our post page and blog, to suggestions for new features, and critical reports on reliability, security, and usability issues.

As part of our ongoing efforts to refine the program, we recently conducted a community-wide review to address discrepancies in qualifying post types. According to the community voting, it has been determined that certain types of post, such as spelling errors, copywriting issues, and less critical cases, will be weighted less significantly in the final evaluation.

Key Changes and Updates:

  1. Introduction of Impact Labels: Based on the voting results, we have introduced a set of labels to categorize qualified posts:
  • Impact Minor: Addresses minor product UI issues, documentation and blog copy errors, edge case bugs, and niche feature suggestions.
  • Impact Medium: Identifies moderate product defects and reasonable feature suggestions that require regular product usage, preferably with latest versions.
  • Impact High: Highlights significant product defects affecting performance, reliability and security, requiring extensive product usage and keen insights.
  • Impact Critical: Addresses critical security issues related and limited to a official services or blocklets, requiring confidential reporting and resolution before public disclosure.
  • Impact Fatal: Addresses fatal security issues related to the blocklet platform, the blockchain or the wallet, requiring confidential reporting and resolution before public disclosure.
  1. July Bug Bounty Review: All Bug Bounty posts submitted in July will undergo a thorough reevaluation. Qualified posts will be labeled with corresponding impact labels. During the final distribution of the monthly reward pool, points will be allocated as follows:
  • Each Impact Minor post will contribute 0.5 point.
  • Each qualified post without any impact label will contribute 1 point.
  • Each Impact Medium post will contribute 2 points.
  • Each Impact High post will contribute 5 points.
  • Each Impact Critical post will contribute 10 points.
  • Each Impact Fatal post will contribute to 50 points.
  1. Calculation Formula: The total points accumulated from a user's qualified posts will determine their share of the reward pool.

These adjustments aim to streamline the Bug Bounty evaluation process and ensure that rewards reflect the significance of the reported issues. We appreciate your continued participation and valuable contributions to improving our platform.

Thank you for your attention and cooperation.

9 条回复

null2年前

good

Brain Titan2年前

Nice explanation🔥

你是好人,我跟你2年前

🚀🚀🚀

wangshijun2年前

Just updated the weight rule for posts with low impact and without any impact labels

Harumi2年前

lfg

wangshijun22个月前

We have added another Impact label: Fatal for security related issue reports, the point contribution is 50, the new label will be used in November 2024.

Brain Titan22个月前(edited)

wow, that’s a lot of points! what would count as a Fatal bug? (examples)

wangshijun22个月前

Usually security issues related to the platform(not a specific blocklet) will be qualified.

akincibor21个月前

This is not fair due to the fact that the pool is capped to 1000 ABT

in a month where there is only 1 minor bug that is qualified = 1000/ (0.5/0.5) = 1000/1 = 1000 ABT

in a month where 1 reporter reported 1 fatal bug and another one 1 fatal bug too = 1000/(100/50) = 1000/2 = 500 ABT each reporter

So someone could earned 1000 ABT in a month for a minor bug while in another month someone will earn 500 ABT for a fatal bug.

That's why I'm currently holding 20+ high critical bugs for the next month because this is not fair

回复