// ITS FOSS — LINUX & OPEN SOURCE
Google Has Shut Down Part of its Open Source Bounty Program
Since 2022, Google's Open Source Software Vulnerability Reward Program (OSS VRP) has been the path for outside researchers to get paid for reporting security flaws in the company's open source code, including projects like Flutter, Angular, Go, and Fuchsia.
With an announcement on X, they have now decided to discontinue the product-facing side of it.
They are calling the change temporary, while supply chain reports remain open and anything submitted before October 1 stays unaffected.
📢 PSA for open-source bug huntersWe are temporarily no longer accepting OSS VRP product vulnerability submissions. This does not impact OSS VRP supply chain reports, or any outstanding reports. As an alternative, we encourage you to find impact across our other VRP programs…
Product vulnerabilities are bugs in the projects themselves, like a failing HTML sanitizer, memory corruption issues in file format parsers, or insecure code examples in documentation.
The updated rules do not limit the change to a specific project tier, as they just won't be accepting any reports related to this.
Supply chain reports, on the other hand, cover vulnerabilities in how the software is built and shipped. Exposed package manager credentials used to publish build artifacts is one case the rules page lists. It remains unaffected by this change.
There's also an exception for some Google Cloud repositories. If a bug there affects a Cloud product, Google may still accept the report, but through its Cloud VRP.
Back in March, a post on the Bug Hunters blog from Google engineers said AI-generated reports were flooding the program. Some were serving up hallucinated information, while others were flagging legit coding errors that had little to no impact on the security posture of the targeted project.
Google's first response was to raise the bar on memory corruption reports for its two top project tiers. Researchers had to either reproduce the bug through an existing OSS-Fuzz fuzz target or point to a patch that maintainers had already merged.