Google stops paying bounties for flaws in Go, Angular and other OSS
EditorialBy TrustList Editorial
The pause follows a surge of automated, mostly invalid submissions. Google's rules page promises an update in the first quarter of 2027 and still accepts supply chain compromise reports.
- Cybersecurity
- Application Security
- Mountain View, Ca
About Google stops paying bounties for flaws in Go, Angular and other OSS
Google stops paying bounties for flaws in Go, Angular and other OSS
1 October 2026: Google no longer accepts product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP), so researchers can no longer claim a reward for security flaws in the code of Google-run open-source projects. The rules page now says the change took effect on 1 October and applies to reports submitted from that date, while earlier reports are unaffected.
Not yet independently verified. We read the rule change in Google's public repository and the reason in press coverage of Google's post on X. Google has given no date for reopening. We will update this when it can be confirmed, and remove this note.
The notice added to the program rules says Google will keep reformatting this part of the program and commits to an update in the first quarter of 2027. In the meantime it suggests researchers look for impact under its other vulnerability reward programs or use its Patch Rewards Program, and it says some Google Cloud repositories may still take product vulnerability reports through the Cloud VRP. The same change removed the listed reward amounts for the two top project tiers, which were $500 to $7,500 for flagship projects and $101 to $3,133.7 for important ones.
The Hacker News reports that Google gave the reason in a post on X on 1 October: a significant rise in automated submissions, most of them not valid. The post gave no figures and did not say whether AI tools produced them. Supply chain compromises, such as flaws that would let someone tamper with a project's source or published packages, keep their rewards, as do other issues like leaked credentials with write access.
The publication lists the flagship tier as 26 repositories, including Go, Angular, Flutter, Bazel and Protocol Buffers, with a further 47 in the important tier. It also notes that Angular's security policy, as of 6 October, still sends vulnerability reports to Google's Bug Hunters site and names no other channel, while Go takes security reports by email to its own security team.
The program was launched in August 2022. In March 2026 Google began requiring stronger proof for reports in some tiers, one accepted form being a patch already merged into the project.
Company profile on TrustList: Google
Sources
Categories & features
- Cybersecurity
- Application Security
- Mountain View, Ca
TrustList Weekly
The week in software and IT, in one email
The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More CybersecurityThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.