PulseAugur
EN
LIVE 16:01:07

Google Halts Open Source VRP Amidst Automated Submission Surge

Google has ceased accepting product-vulnerability reports via its Open Source Software Vulnerability Reward Program (VRP) as of October 1st. This decision follows a significant increase in automated submissions, which the company stated were largely invalid. While supply-chain vulnerability reports continue to be accepted, Google anticipates updating the program in the first quarter of 2027. The company noted that while AI can aid in bug discovery, reproducible evidence is crucial for maintainers to effectively triage such findings. AI

IMPACT AI-assisted vulnerability discovery requires careful validation to avoid overwhelming security programs.

RANK_REASON A company is changing its policy for a specific program, impacting how external researchers report vulnerabilities.

Read on Mastodon — mastodon.social →

AI-generated summary · Google Gemini · from 1 sources. How we write summaries →

Google Halts Open Source VRP Amidst Automated Submission Surge

How we ranked this

Signal score
4 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
A company is changing its policy for a specific program, impacting how external researchers report vulnerabilities.
Source corroboration
Single-source cluster
Only one publisher covered this so far. Single-source stories can still rank when the publisher is high-authority, but they lack cross-source corroboration.
Topics
policy, product, other
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
Standard
On-topic for AI-industry coverage; kept in the public index.
Story freshness
Breaking (< 6h)
Fresh story with cross-source coverage still developing. Ranking may shift as more sources report.

Full methodology in our editorial standards.

COVERAGE [1]

  1. Mastodon — mastodon.social TIER_1 English(EN) · [email protected] ·

    Google stopped accepting product-vulnerability reports through its Open Source Software VRP on Oct. 1 after a surge in automated submissions it says were mostly

    Google stopped accepting product-vulnerability reports through its Open Source Software VRP on Oct. 1 after a surge in automated submissions it says were mostly invalid. Supply-chain reports are still accepted, and Google plans an update in Q1 2027. AI can help find bugs, but fin…