Skip to content
TrustList
News

Google stops paying bounties for flaws in Go, Angular and other OSS

Editorial

By TrustList Editorial

The pause follows a surge of automated, mostly invalid submissions. Google's rules page promises an update in the first quarter of 2027 and still accepts supply chain compromise reports.

About Google stops paying bounties for flaws in Go, Angular and other OSS

Google stops paying bounties for flaws in Go, Angular and other OSS

1 October 2026: Google no longer accepts product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP), so researchers can no longer claim a reward for security flaws in the code of Google-run open-source projects. The rules page now says the change took effect on 1 October and applies to reports submitted from that date, while earlier reports are unaffected.

Not yet independently verified. We read the rule change in Google's public repository and the reason in press coverage of Google's post on X. Google has given no date for reopening. We will update this when it can be confirmed, and remove this note.

The notice added to the program rules says Google will keep reformatting this part of the program and commits to an update in the first quarter of 2027. In the meantime it suggests researchers look for impact under its other vulnerability reward programs or use its Patch Rewards Program, and it says some Google Cloud repositories may still take product vulnerability reports through the Cloud VRP. The same change removed the listed reward amounts for the two top project tiers, which were $500 to $7,500 for flagship projects and $101 to $3,133.7 for important ones.

The Hacker News reports that Google gave the reason in a post on X on 1 October: a significant rise in automated submissions, most of them not valid. The post gave no figures and did not say whether AI tools produced them. Supply chain compromises, such as flaws that would let someone tamper with a project's source or published packages, keep their rewards, as do other issues like leaked credentials with write access.

The publication lists the flagship tier as 26 repositories, including Go, Angular, Flutter, Bazel and Protocol Buffers, with a further 47 in the important tier. It also notes that Angular's security policy, as of 6 October, still sends vulnerability reports to Google's Bug Hunters site and names no other channel, while Go takes security reports by email to its own security team.

The program was launched in August 2022. In March 2026 Google began requiring stronger proof for reports in some tiers, one accepted form being a patch already merged into the project.

Company profile on TrustList: Google

Sources

Categories & features

TrustList Weekly

The week in software and IT, in one email

The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.

We will email you to confirm. Unsubscribe with one click in any issue. Privacy policy