{"rewrite":{"id":"r_86ee93e72449af1c9e88b2cb","clusterId":"c_40874d7820ec27453dc417ca","slug":"google-halts-open-source-bug-bounty-submissions-after-surge-in-automated-reports","model":"deepseek-v4-1-flash","headline":"Google Halts Open Source Bug Bounty Submissions After Surge in Automated Reports","summary":"Google stopped accepting product vulnerability reports for its Open Source Software Vulnerability Reward Program as of October 1, 2026. The company cited a significant rise in automated submissions, most of them invalid. Supply chain reports and outstanding reports are unaffected. Google says it will reformat the program and give an update in Q1 2027. Some Google Cloud repositories still take reports through Google Cloud VRP.","whyItMatters":"A program built to pay humans for finding real flaws is now spending its time filtering machine-generated noise, and the same pressure has already pushed cURL and HackerOne to change how they take reports.","webCardHtml":"\u003cp\u003eProduct vulnerability reports for the Google OSS VRP closed on October 1, 2026. The rules page now says the program is no longer accepting them. Reports tied to some Google Cloud repositories can still go through Google Cloud VRP, and supply chain reports continue as before.\u003c/p\u003e\u003cp\u003eGoogle attributes the pause to automated submissions that are mostly invalid or unexploitable. Engineers and maintainers end up verifying code instead of fixing it. The company says it will reformat this part of the program and post an update in Q1 2027.\u003c/p\u003e","blueskyPost":"Google's VRP pause leaves valid researchers competing against bots for triage attention. Reporting channels stay open, so the quieter damage is response time on real Open Source flaws.","twitterPost":"Pausing one Google VRP stream does not stop reports. It shifts valid researchers into queues now shared with automated noise.","threadsPost":"Google Cloud VRP still accepts reports, so the pause is not a blanket halt. It concentrates valid submissions into a channel where automated noise now competes for the same triage attention.","newsletterBlurb":"Google closed product vulnerability submissions for its Open Source Software Vulnerability Reward Program on October 1, 2026, pointing to a significant rise in automated reports that are mostly invalid. Supply chain reports and outstanding reports are unaffected, and some Google Cloud repositories still route through Google Cloud VRP. Google says it will rework this part of the program and update in Q1 2027.","attributionJson":"[{\"source\":\"GIGAZINE\",\"url\":\"https://gigazine.net/news/20261005-google-froze-open-source-bug-bounty-program/\",\"title\":\"Google Suspends Bug Bounty Program After Explosion of AI-Generated Bug Reports\"}]","lintFlagsJson":null,"lintHits":0,"costUsd":0,"inputTokens":4747,"outputTokens":559,"status":"published","repairAttempts":0,"nextRepairAt":null,"factsAttemptedAt":1791263228,"createdAt":"2026-10-06T05:04:05.000Z","publishedAt":"2026-10-06T05:06:06.000Z","updatedAt":"2026-10-06T05:06:06.000Z"},"cluster":{"id":"c_40874d7820ec27453dc417ca","canonicalTitle":"AIによるバグ報告が爆増したためGoogleがバグ報奨金プログラムを一時停止","representativeArticleId":"a_66e8bffee6fbadae1a4e66e1","sourceCount":1,"writtenSourceCount":1,"writeAttempts":0,"isSolo":true,"entitiesJson":"{\"anime_titles\":[],\"manga_titles\":[],\"work_titles\":[],\"studios\":[],\"people\":[],\"type\":\"news\",\"domain\":\"other\",\"is_roundup\":false}","contentType":"news","status":"published","firstSeenAt":"2026-10-05T02:55:00.000Z","lastSeenAt":"2026-10-05T02:55:00.000Z","updatedAt":"2026-10-06T05:06:06.000Z"},"attribution":[{"source":"GIGAZINE","url":"https://gigazine.net/news/20261005-google-froze-open-source-bug-bounty-program/","title":"AIによるバグ報告が爆増したためGoogleがバグ報奨金プログラムを一時停止"}],"entities":{"anime_titles":[],"manga_titles":[],"work_titles":[],"studios":[],"people":[],"type":"news","domain":"other","is_roundup":false},"keyFacts":null}
