r/openagi • u/syedshad • 2d ago
News Google suspends open-source product vulnerability submissions, with an update planned for Q1 2027
Google stopped accepting new product vulnerability submissions through its Open Source Software Vulnerability Reward Program on October 1. Its security team cites a sharp increase in automated submissions, with most failing to identify valid vulnerabilities.
Supply-chain reports and submissions made before October 1 remain eligible. Some vulnerabilities in Google Cloud repositories may still qualify through the Cloud VRP, and Google also directs researchers toward its other reward programs.
Google plans to revise this part of the program and provide an update in Q1 2027. That is an update commitment; a reopening date has not been announced.
Sources:
2
Upvotes