"a significant rise in automated submissions, the vast majority of which are not valid," Google said on October 1, explaining why it has stopped accepting product vulnerability reports for its open-source software through its Open Source Software Vulnerability Reward Program (OSS VRP).
Google pauses product-vulnerability rewards in the OSS VRP
Effective October 1, Google has suspended the part of the OSS VRP that accepted reports of product vulnerabilities in its open-source code. Researchers can no longer submit such reports there for a reward; reports filed before October 1 are not affected. Google described the suspension as temporary in a post on X and said it will rework that portion of the program with an update committed for the first quarter of 2027. The post gave no figures and "did not say whether the submissions were produced with AI tools."
Tiers, removed bounty amounts, and named repositories
The OSS VRP groups projects into four tiers based on sensitivity. Only the top two tiers — labelled flagship and important — previously carried listed rewards for product vulnerabilities. Google published a change to the program rules on its public GitHub copy on September 30 that removed those listed amounts. The removed ranges were $500 to $7,500 for flagship projects and $101 to $3,133.7 for important projects.
Google's publicly posted list of tiered repositories, last updated in mid-September, names 26 flagship repositories and 47 important ones. The flagship tier includes Go, Angular, Flutter, Bazel, and Protocol Buffers. The fourth tier, for low-priority projects, has no listed rewards.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleWhat Google will still take: supply chain reports and other categories
The OSS VRP pause applies to product vulnerabilities but not to supply chain compromises. Supply chain compromises — flaws that could let someone tamper with a project's source code or published packages — retain their listed rewards. Other security issues, such as leaked credentials that give write access, also continue to be eligible under the program's existing rules.
Alternate submission routes: Cloud VRP, Patch Rewards, and other programs
Google's notice directs researchers toward three alternative routes.
- Cloud VRP: Product vulnerability reports may still be accepted for some Google Cloud repositories that affect Google Cloud products, though the notice does not name which repositories. Under the Cloud VRP rules, a flaw in an open source repository maintained by Google Cloud that affects Cloud products is rated at most IT3b, the tier for acquisitions and lower-priority products; that cap applies unless Google's product list says otherwise.
- Patch Rewards: The Patch Rewards Program pays between $100 and $15,000 for security patches to projects it covers, not for vulnerability reports. To be eligible, a project's maintainers must accept a patch and remain in place for one month before it can be submitted. The program will review patches that fix only a single vulnerability on a case-by-case basis.
- Other reward programs: Google asks researchers to check whether a flaw affects something covered by one of its other reward programs and to submit it there. The OSS VRP rules explicitly encourage reporting flaws in projects closely tied to Google Cloud or AI products to the Cloud VRP or the AI VRP.
The notice does not say whether Google will accept product vulnerability reports without offering a reward.
Project-level policies: Go, Angular, and GitHub guidance
Some individual project policies already point researchers to alternate channels. The Go project takes security reports by email to its own security team. A security policy in Google's GitHub organization directs reporters to Google's vulnerability reporting address, g.co/vulnz. Angular's security policy, as of October 6, states that Angular is part of the OSS VRP, sends vulnerability reports to Google's Bug Hunters site, and names no other channel.
Earlier tightening and LLM-related guidance
Google launched the OSS VRP in August 2022. In March 2026, the program began requiring stronger proof for reports in some tiers to filter out low-quality submissions; a patch already merged into the project is one accepted form of proof. InfoWorld reported at the time that the program's team was concerned about the low quality of some AI-generated submissions, many of which included invented details about how a vulnerability could be triggered.
Separately, the Go project's security policy added a section in early September on reports generated by large language models (LLMs). It asks reporters "not to send such reports without reviewing and filtering them first" and states: "LLMs are good at finding real security bugs and just as good at reporting ones that do not exist. Reporters who forward large amounts of unfiltered LLM output will not be credited for their findings."
What this means for security researchers, open-source maintainers, and enterprises
Security researchers: For product vulnerabilities in Google's open-source repositories, researchers lose the OSS VRP reward route until Google reopens that part of the program; they can still examine Cloud VRP eligibility, submit accepted patches to the Patch Rewards Program, or look for other applicable Google reward programs.
Open-source maintainers: Maintainers may continue to receive supply-chain and credential-related reports via the OSS VRP and can accept patches submitted under the Patch Rewards Program (subject to the one-month maintainer condition and case-by-case review for single-vulnerability fixes).
Enterprises and procurement leaders: Supply chain compromise reports remain eligible for rewards, preserving an incentive to surface tampering risks that can affect downstream users and packages built from Google's open-source libraries.
Google removed the publicly listed product bounty amounts on September 30 and said it will update the OSS VRP in the first quarter of 2027. The company has not provided dates for resuming product-vulnerability rewards, nor has it stated whether it will accept unrewarded product vulnerability reports in the meantime — specific answers that researchers and maintainers will be watching for as the program is reworked.




