# New HackerOne Signal Requirement for Vulnerability Reports

DevFeed: [New HackerOne Signal Requirement for Vulnerability Reports](<https://devfeed.tech/articles/new-hackerone-signal-requirement-for-vulnerability-reports-2419.md>)

Original publisher: [Read original article](<https://nodejs.org/en/blog/announcements/hackerone-signal-requirement>)

Published: 2026-02-19T12:00:00Z

Content type: news

Language: en

Sources: [Node.js Blog](<https://devfeed.tech/sources/node-js-blog.md>)

Topics: [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Node.js](<https://devfeed.tech/topics/node-js.md>), [Security](<https://devfeed.tech/topics/security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Slack](<https://devfeed.tech/topics/slack.md>)

Tags: [node-js](<https://devfeed.tech/tags/node-js.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [slack](<https://devfeed.tech/tags/slack.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

## AI overview

Node.js повысes the HackerOne Signal requirement for vulnerability reports to 1.0 or higher after a rise in low-quality submissions. Researchers below the threshold can contact the Node.js security release stewards through the OpenJS Foundation Slack.

## Source excerpt

Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.