importantSYS.SOURCE: The Hacker News• 2026-10-06T14:51:47+05:30
Google Temporarily Halts OSS Product Bug Bounty Rewards Due to Automated Report Surge
Google has temporarily paused its Open Source Software Vulnerability Reward Program (OSS VRP) for product vulnerabilities due to a surge in invalid automated reports, with plans to revise the program by Q1 2027. Supply chain compromise reports and other security issues remain eligible for rewards under alternative programs.
Google has stopped accepting product vulnerability reports through its bug bounty program for its open-source software.
The change, in effect since October 1, means researchers can no longer submit security flaws in the code of projects such as Go, Angular, and Protocol Buffers there for a reward. Reports about supply chain compromises are still accepted, and reports filed before October 1 are
*** END OF TRANSMISSION ***