According to GitHub, the changes aim to reduce administrative noise so that the security team can focus on legitimate, actionable security signals.
The new system introduces a two-tier reward structure that drastically cuts payouts for public submissions.
Rewards for critical vulnerabilities in the public program have been reduced from $30,000 to a maximum of $10,000, while low-severity findings have been halved to $250.
Conversely, a new invite-only VIP tier will offer significantly higher payouts, starting at $30,000 for critical flaws.
To qualify for this elite group, researchers must demonstrate a proven history of valid submissions, such as at least one accepted critical vulnerability or several lower-severity findings.
In addition to the reward changes, GitHub is implementing a signal requirement that limits the number of reports new researchers can submit until they have established a track record of accuracy.
While newcomers will still have initial opportunities to prove their expertise, the platform is prioritizing depth over breadth to manage the current backlog.
Reports already submitted before the changes take effect will continue to be assessed under the previous payout structure.