blst-security / cherrybomb

Stop half-done APIs! Cherrybomb is a CLI tool that helps you avoid undefined user behaviour by auditing your API specifications, validating them and running API security tests.

Home Page:https://www.blstsecurity.com/cherrybomb

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Active/Passive Checks Needed

RazMag opened this issue · comments

New Active / Passive Checks

We are excited to announce our new bounty program!
Starting today and following the release of version v0.7.0 were offering bounties for merged PRs of new checks, active and passive opened before the end of 2022.

Conditions

Bounties will be issued for merged PRs of new checks opened before the end of 2022.

  • Active checks: $30
  • Passive checks: $15

Writing A New Check

Contribution help can be found on the repo. If you feel the need to change any other file than the ones mentioned in the CONTIBUTING.md file feel free to talk with raz.m@blstsecurity.com, nathan.s@blstsecurity.com or on the discord https://discord.gg/prSZHvdVjq.

Choosing A New Test To Write

Easiest way to choose a check to write will be visiting the [issues page](is:issue is:open label:"New passive check","New active check") in the repo.
For more inspiration you can visit OWASP API Security Project or the PortSwigger Web Security Academy and see if you find anything you think could be automated.
If you are solving an existing issue make sure it has the "bounty" label

Raffle

We would also like to offer a raffle depending on the amount of people that will open PRs.
Currently if 10 different people will have their PRs merged we will hold a Raffle between the contributors of company swag!