Subdomains under *.githubapp.com provide a number of internal services to GitHub employees. These include our internal blog, helpdesk and bastion access to our internal network.

Focus areas

Ineligible submissions

Vulnerabilities in out-of-scope subdomains

Not all subdomains are in-scope for rewards at this time and are therefore ineligible for rewards. A list of out-of-scope subdomains is available in our scope section.

Submit a vulnerability for *.githubapp.com