Jump to content
Silhouette of a woman holding an analog megaphone.

Calling All Security Researchers: Help Make Our Digital Infrastructure Safer

By Tara Tarakiyee

In Resilience

We're calling on security researchers to help enhance the resilience of open digital infrastructure. Participate in the bug & fix bounties of seven critical software projects.

Given enough eyeballs, all bugs are shallow.

The openness of open digital infrastructure is not something to be taken for granted. The more critical a software project is, the more challenging proper vulnerability management becomes. However, as the software development adage above suggests, combining openness with increased collaboration and scrutiny simplifies the task. This principle is a cornerstone of the Bug Resilience Program’s (BRP) approach to enhancing the resilience of open digital infrastructure. It applies to reducing technical debt and improving contribution guidelines via our direct contributions service, as well as to the code audit service.

This principle is most apparent in our bug & fix bounty program on the YesWeHack platform. Here, we aim to bring as many experts as possible to examine the code that underpins our digital lives and improve its resilience and security. Security researchers, bug hunters, and hackers work tirelessly, often at great personal risk, to find and fix vulnerabilities before malicious actors can exploit them. By applying their knowledge and expertise to uncover vulnerabilities in currently deployed technology infrastructure, they help provide an active defense against undiscovered vulnerabilities.

At BRP, we emphasize responsible disclosure, as we provide services to software projects used and relied upon by millions. Responsible disclosure ensures that discovered vulnerabilities are reported in a manner where they can be remediated and announced in a way that minimizes any potential abuse or damage occurring to the users of affected software.


What kind of software would researchers be looking at?

We are thrilled to announce five new bug bounty programs in addition to the two already available. More bug bounty programs will be added throughout the year. If you’re responsible for an open digital infrastructure software project, learn more about how to apply for support.

Existing Bug Bounty Programs

  • systemd is a suite of basic building blocks for a Linux system. It provides a system and service manager that runs as PID 1 and starts the rest of the system.
    More on the systemd bug bounty
  • Sequoia PGP provides several secure communication and authentication solutions in the OpenPGP space, including a low-level PGP implementation written in Rust.
    More on the Sequoia PGP bug bounty

New Bug Bounty Programs


How to Get Involved

  • Get rewarded for discovering a qualifying vulnerability! Select a software project that aligns with your interest and expertise, read the scope carefully, do your research, and submit your reports through the YesWeHack platform!
  • Share the program with your communities. We strongly believe in leveraging collective knowledge and fostering a culture of collaboration and security in open digital infrastructure, and we can’t do that without your help.

Your skills, dedication, and expertise can make a profound difference. Together, we can further ensure the resilience and safety of our critical open digital infrastructure.


More articles

All articles

  • News

    Read article: Open, Resilient, European: The EDIC Digital Commons

    The European Commission has announced the creation of the EDIC Digital Commons — a major milestone in a multi-year European effort that the Sovereign Tech Agency helped shape from the start, advancing open, interoperable, and sustainable digital infrastructure across Europe.

  • Tara, Mirko, Paloma, and Powen at Open Source Summit Europe in Amsterdam
    Newsletter

    Read article: Newsletter: New Technology Investments, Sessions at Open Source Summit, and Sovereign Tech Fellowship Highlights

    Email newsletter on 21 October 2025: the Sovereign Tech Fund's latest technology investments, an in-depth interview with Sovereign Tech Fellow Jan Kowalleck, and video recordings from our sessions at Open Source Summit Europe in Amsterdam and FrOSCon.

  • News

    Read article: Meet Sovereign Tech Fellow Jan Kowalleck

    Open source maintainer Jan Kowalleck began his journey with OWASP CycloneDX by fixing a single bug. That small step led to becoming Project Co-Lead, mentoring new contributors, and helping shape the international standard for software transparency. In this interview, Jan shares how he balances maintenance and community building, why SBOMs are key to software security, and what it takes to guide a fast-growing open source project.