Google's open-source bug bounty aims to clamp down on supply chain attacks

Posts from this topic will be added to your daily email digest and your homepage feed.

Google's open-source bug bounty aims to clamp down on supply chain attacks

TL;DR

  • Google's new program rewards researchers for finding security flaws in its open-source software and its dependencies.
  • The initiative aims to address supply chain attacks, where attackers target third-party code used by larger projects.
  • Payouts range from $101 to $31,337, depending on the severity of the bug and the importance of the project.
  • Researchers must report vulnerabilities in third-party projects to the project maintainers first before notifying Google.
  • The program covers bugs that affect Google's projects, excluding issues with third-party services or platforms used by Google.
  • Researchers can opt to donate their rewards to charity, with Google doubling the donation amount.
  • This initiative follows concerns raised by Google about the need for better security in critical open-source projects, particularly after the Log4Shell exploit.