Google's open-source bug bounty aims to clamp down on supply chain attacks
Posts from this topic will be added to your daily email digest and your homepage feed.

TL;DR
- Google's new program rewards researchers for finding security flaws in its open-source software and its dependencies.
- The initiative aims to address supply chain attacks, where attackers target third-party code used by larger projects.
- Payouts range from $101 to $31,337, depending on the severity of the bug and the importance of the project.
- Researchers must report vulnerabilities in third-party projects to the project maintainers first before notifying Google.
- The program covers bugs that affect Google's projects, excluding issues with third-party services or platforms used by Google.
- Researchers can opt to donate their rewards to charity, with Google doubling the donation amount.
- This initiative follows concerns raised by Google about the need for better security in critical open-source projects, particularly after the Log4Shell exploit.