Over half a million dollars have been awarded in rewards to security researchers participating in GitHub's bug bounty program over the past year, bringing the total to $1.5 million.
See also: Hacker won $2 million in bug bounty programs!

GitHub has been running the GitHub Security Bug Bounty program for seven years.
Bug bounty programs are now very popular and more and more companies and services are asking security researchers to scan their systems for potential vulnerabilities, for a fee.
“From February 2020 to February 2021, we handled the highest volume of reports than any previous year,” GitHub says.
A total of 1,066 bug reportsover the past year to GitHub's public and private programs (the latter focusing on betas and other products that haven't been released yet). It also awarded $524,250 for 203 vulnerabilities. Since GitHub launched its public program on HackerOne, the rewards have now reached $1,552,004.
See also: GitHub: Developers will upload videos to their repositories
The scope of GitHub's bug bounty program includes many GitHub-owned domains and other assets, such as the GitHub API, Actions, Pages, and Gist. Reporting critical vulnerabilities (e.g., those that allow code execution, SQL attacks, and login bypass) can earn researchers up to $30,000.

GitHub also operates under the Safe Harbor, which says that bug hunters who disclose vulnerabilities responsibly and in accordance with company policies are protected from potential legal consequences of their research.
The company also said that over the past year, an open redirect vulnerability has been the platform's "favorite" bug. William Bowling was able to develop an exploit that showed how this vulnerability on GitHub.com could compromise Gist user OAuth flows.
See also: How to quickly and easily delete a GitHub repository?
Bowling managed to earn $10,000 for reporting this particular vulnerability.
GitHub also gained CVE Number Authority (CNA) status in 2020 and has begun issuing CVE IDs for vulnerabilities in GitHub Enterprise Server.
Source: ZDNet
