Google suspended its open source vulnerability rewards program
Google suspended its open source vulnerability rewards program as of 1 October. According to the company, the reason is an increase in automated reports, the vast majority of which are invalid. It promises further information in the first quarter of 2027.
According to the article, invalid automated reports overwhelmed engineers and open source maintainers at Google. This has affected the process of receiving and validating security reports.