Google freezes its open-source bug bounty after a flood of invalid AI-generated reports
As of Oct 1, Google's OSS VRP no longer takes product vulnerability reports for projects like Go, Angular, and Protocol Buffers, citing "a significant rise in automated submissions, the vast majority of which are not valid"; supply-chain reports and anything filed earlier still count, with an update promised in Q1 2027. If you point agents at bug hunting, validate findings yourself before filing, or route them to Google's other VRPs or the Patch Rewards Program.