search
OSS VRP
Trends
- 1Google stops accepting product vulnerabilities in open-source bug bounty●Google no longer accepting product vulnerabilities submitted to the OSS VRP
Google has updated the rules of its Open Source Software Vulnerability Reward Program so that it no longer accepts reports of product vulnerabilities, directing researchers away from submitting such findings through the OSS VRP. The change limits the program's scope to open-source projects only, and security researchers are debating where product-related flaws should now be reported.