Google has tightened the rules of its OSS Vulnerability Reward Program following a surge in low-quality and invalid AI-generated security reports.
Google has tightened the rules of its OSS Vulnerability Reward Program following a surge in low-quality and invalid AI-generated security reports.
The company is narrowing rewards and triage for some open-source project tiers while requiring stronger evidence, such as reproducible proof or a merged patch, for higher-priority projects. Google’s official announcement describes a restructuring of OSS VRP rather than a complete suspension of the program.