Skip to content

Imports ​

Galileo imports authorized bug bounty programs into Hashiro projects and maps their included and excluded targets into scope. It uses your normal Hashiro profile plus separate source-platform credentials.

Prerequisites ​

Configure the Hashiro connection and use an account allowed to create projects. Add the relevant platform section to config.toml:

toml
[hackerone]
username = "YOUR_HACKERONE_USERNAME"
api_key = "YOUR_HACKERONE_API_TOKEN"

[intigriti]
api_key = "YOUR_INTIGRITI_API_TOKEN"

These platform credentials are separate from the Hashiro api_key. Add only the sections you use.

HackerOne ​

bash
galileo import hackerone

Alias: h1. Galileo uses your HackerOne username and API token, fetches available programs, creates projects, and imports included and excluded targets. Review the output for per-program errors.

Intigriti ​

bash
galileo import intigriti

Alias: int. Galileo uses the Intigriti bearer API token, retrieves accessible programs, and imports project information and scope. Programs without usable scope or a program ID may be skipped.

Verify the result ​

bash
galileo projects list
galileo projects inscope --project PROGRAM_NAME
galileo projects outscope --project PROGRAM_NAME

Review the imported entries against the current program rules. Imported scope does not replace authorization or the source platform's restrictions. Imports may partially complete; review errors before retrying.

Scope mapping ​

Domains and wildcard targets become corresponding scope entries. Mobile application and source-code entries retain their platform-specific classification where supported. Review unusual target types after import instead of assuming every external type maps identically.

Hashiro. Continuous Threat Exposure Management.