Skip to main content
This changelog records notable additions, improvements, and fixes to the Hackrate platform. It leaves out routine maintenance, copy edits, and small visual adjustments.
  • September 29 — Improved: Report administration shows clearer controls, and analytics gained more detailed cost-control views.
  • September 28 — Added: Report management shows linked duplicate reports alongside the pre-validation assessment.
  • September 28 — Improved: The bonus workflow gained clearer handling when administrators review rewards.
  • September 27 — Improved: Hall of Fame views show more researcher recognition details.
  • September 25 — Added: Administrators can share bounty details by email and resend an administrator invitation.
  • September 25 — Fixed: Stale-report reminders exclude known issues.
  • September 22 — Fixed: Reward handling and analytics account for report-level known issues.
  • September 21 — Added: The external admin API v1 supports programmatic organization workflows. Endpoint definitions are in the API reference tab.
  • September 18 — Added: Program teams can submit known issues, and the platform gained an in-app notification system.
  • September 18 — Added: The Linear integration synchronizes issues in both directions.
  • September 18 — Improved: Administrators without super admin access can switch to all-report statistics where permitted.
  • September 14 — Added: The organization bounty ledger brings reward activity into one view.
  • September 12 — Added: A bounty program switch controls whether a program offers monetary rewards.
  • September 9 — Added: Program teams can set researcher participation requirements.
  • September 9 — Added: Individual users can suppress Slack notifications.
  • September 8 — Added: Manage bounty tables in program settings, including table creation.
  • September 8 — Added: An analytics role and expanded organization analytics provide more targeted access to reporting data.
  • September 8 — Added: Embedded report forms can resize their hosting iframe.
  • September 7 — Added: Manage scope directly and notify researchers when scope changes.
  • September 7 — Improved: The GitHub integration can link multiple issues or security advisories to a report.
  • September 6 — Added: Configure program test credentials and restart a paused program from its management view.
  • September 3 — Added: Public researcher profiles and a public leaderboard make researcher activity discoverable.
  • September 1 — Added: Filter advanced report views by target.
  • August 31 — Added: Write a custom resolution message when closing a report.
  • August 31 — Added: A Dropzone authorization API supports VDP onboarding and its extra-points flow.
  • August 27 — Added: Create GitHub Security Advisories for accepted reports through the GitHub integration.
  • August 27 — Improved: The Jira integration gained advanced field mappings.
  • August 26 — Added: Invite super administrators through the team management flow.
  • August 21 — Added: Copy a complete report when you need to share its details.
  • August 21 — Improved: Report filters cover all severity and status values, and the scope table shows a tier column.
  • August 21 — Added: Jira advanced configuration guidance and a program start action.
  • August 15 — Added: Program owners can pause or stop a program.
  • August 15 — Added: A public API exposes published Hacktivity entries.
  • August 10 — Changed: Account authentication and user management began moving to Clerk.
  • August 1 — Added: Jira gained two-way issue synchronization.
  • July 26 — Added: Customize the branding of an embedded VDP form.
  • July 26 — Added: Add custom fields to report submissions, including up to three program-specific questions.
  • July 22 — Improved: The researcher identity verification flow gained a new version.
  • July 20 — Improved: The leaderboard gained a redesigned experience.
  • July 19 — Added: Researchers gained a My Profile view.
  • July 18 — Improved: Report pre-validation provides more context before triage.
  • July 16 — Fixed: Bounty totals include bonuses, and embedded-form reporters can view the associated program details.
  • July 12 — Added: Publish eligible reports to Hacktivity and manage CVE requests.
  • July 1 — Added: Move a report to a different program or target when it was submitted to the wrong place.
  • June 30 — Added: Administrators can view reports across an organization.
  • June 29 — Added: Reward controls restrict duplicate bounties.
  • June 10 — Added: A new reports view helps teams work through incoming findings.
  • June 10 — Added: Program teams can change VDP text and send email after a report’s program changes.
  • June 6 — Fixed: Group authorization checks were tightened, and notifications no longer email users about their own actions.
  • May 7 — Added: Upload credentials for program testing.
  • April 28 — Added: Manage multiple layers of test credentials for a program.
  • April 24 — Improved: Configure the GitHub integration across an organization, and review team summaries.
  • April 23 — Added: Stale-report reminders and email preview help administrators manage follow-up.
  • April 19 — Added: GitHub Security Advisory integration.
  • April 17 — Added: Comments on linked GitHub issues and a GitHub-supported report pre-validation workflow.
  • February 28 — Added: Researcher invitations show location and two-factor authentication information.
  • January 9 — Added: Structured CVE and CWE data expanded report and team summary records.
  • December 17 — Improved: Analytics calculate average bounty by severity.
  • December 8 — Added: Expanded organization analytics and administrator join emails.
  • November 28 — Improved: Report management shows CVSS information and the assigned team member.
  • November 25 — Added: Assign reports to team members from the management view.
  • November 2 — Improved: The main access-control rules were revised for organization workflows.
  • September 26 — Added: Select filters and columns when exporting report data to CSV.
  • September 22 — Added: Publish program announcements to researchers.
  • September 16 — Added: Bonus rewards and program pause controls.
  • September 5 — Added: Store program test credentials and assign VDP reporters.
  • August 4 — Added: Business units help organize administrator access and program work.
  • July 24 — Added: Set a bounty limit for a program.
  • July 24 — Fixed: Performance improvements addressed timeouts in program details, management, analytics, and the catalog.
  • July 8 — Added: Program report tables retain their selected view state.
  • June 9 — Added: Administrator invitations, a new scope table, and updated settings views.
  • June 9 — Improved: Report actions include Accepted risk, and getting-started guidance checks the administrator role.
  • March 30 — Added: An email alias integration for program communications.
  • March 17 — Added: Mark a finding as Accepted risk when your organization acknowledges it without immediate remediation.
  • December 12 — Added: Back-office notifications for closed reports that receive a bounty.
  • November 13 — Added: Invite administrators through a dedicated team workflow.
  • November 6 — Added: Researcher notification sending and more analytics views.
  • September 7 — Added: Review pending and declined administrator invitations.
  • April 7 — Added: Program catalog discovery and expired-invitation analytics.
  • April 7 — Fixed: Disabled targets no longer appear in the catalog.
  • October 23 — Improved: CSV exports reflect the exporting administrator’s permissions.
  • October 2 — Added: Invitation expiry is visible in administration.
  • September 18 — Added: A dedicated pending reports view for incoming findings.
  • September 16 — Fixed: Webhook access checks respect permissions.
  • July 30 — Added: Private programs gained description content in discovery.
  • July 22 — Added: A CVSS calculator in reporting and private programs in the public catalog.
  • October 23 — Added: Two-factor authentication controls in account settings.
  • October 22 — Added: Markdown preview for program management fields and easier navigation between analytics and program management.
  • October 9 — Added: A dynamic notification bar for platform messages.
  • June 9 — Added: Slack integration for report activity.
  • June 8 — Added: Microsoft Teams integration for report activity.
  • May 15 — Added: Secured certificates for programs.
  • May 7 — Improved: Administrator triage gained a ban action and updated out-of-scope and informative severity handling.
  • October 15 — Changed: A major platform redesign refreshed the application.
  • October 12 — Added: File validation for uploaded evidence.
  • July 29 — Improved: Reports gained structured attachment metadata.
  • July 20 — Improved: The embedded VDP report form and its related services.
  • June 23 — Improved: Markdown rendering gained sanitization for submitted content.
  • June 16 — Added: Markdown preview in the reporting experience.
  • June 1 — Added: Internal report comments.
  • May 26 — Added: Dedicated storage and queue processing for report evidence.
  • May 19 — Added: Verification updates, report status badges, and larger evidence uploads.