Skip to content

Track HackerOne reports and leaderboard changes on programs through a Discord webhook

License

Notifications You must be signed in to change notification settings

hackermondev/hackerone-tracker

Repository files navigation

HackerOne tracker

GitHub stars License

Overview

Monitor HackerOne reports and track changes in the leaderboard of programs using a Discord webhook.

It uses the HackerOne GraphQL API to poll for new reports and leaderboard changes every 5 minutes, then sends a message to the webhook you conifugre.

HackerOne reputation overview showcase

Installation

Clone the repository (requires Docker and Docker Compose):

git clone https://github.com/hackermondev/hackerone-tracker

or clone on Replit:
Run on Repl.it

Setup your configuration (config.example.yaml):

discord:
  redis: redis:https://redis:6379 # Don't change this if you're using the default Docker compose/Replit configuration
  webhook_url: "" # Discord webhook URL (the format has to be: https://discord.com/api/webhooks/{webhook_id}/{webhook_token})

poller:
  redis: redis:https://redis:6379 # Don't change this if you're using the default Docker compose/Replit configuration
  handle: "" # HackerOne team handle
  session_token: "" # HackerOne session token (the "__Host-session" cookie), this is only required if you're tracking a private team

(If you're entering your session token and using Replit, make sure your repl is set to private. You'll also need to make sure you're logged in with HackerOne on the "2 weeks" session option and update your session token every 2 weeks in config)

If you're wish to track leaderboard changes and reports in all public programs, simply remove the handle: "" line.

After entering your config, rename the file to config.yaml. If you're using Replit, simply click the Run button, otherwise with Docker compose run: sudo docker compose up --build -d. Wait for it to build (this can take up to 5 minutes) and then you should now be tracking the leaderboad changes.

If you're using Replit, make sure to enable "Always On" with Replit to ensure it keeps running.

Contributing

Pull requests are welcome. For major changes, please open an issue first to discuss what you would like to change.