search
OSS Vulnerability Reward Program
Trends
- 1Google stops accepting product vulnerabilities in OSS bug bounty●Google no longer accepting product vulnerabilities submitted to the OSS VRP
Google has stopped accepting product vulnerability reports through its Open Source Software Vulnerability Reward Program, directing researchers to other reporting routes for those issues. The change, visible on the program's rules page, is drawing attention in the security community, with researchers debating whether the narrowing of scope reduces the program's usefulness for hardening widely used open source dependencies.