Active Stocks
Tue Apr 16 2024 09:34:34
  1. Tata Steel share price
  2. 162.25 0.84%
  1. NTPC share price
  2. 359.25 -0.58%
  1. HDFC Bank share price
  2. 1,487.85 -0.47%
  1. Power Grid Corporation Of India share price
  2. 275.20 0.38%
  1. Infosys share price
  2. 1,450.75 -1.20%
Business News/ Technology / News/  Google to pay 25 lakh to find bugs in its open source projects
BackBack

Google to pay ₹25 lakh to find bugs in its open source projects

The newly announced Vulnerability Reward Program (VRP) will focus on Google software and repository settings like GitHub actions, application configurations, and access control rules.

Google announces new bug bounty programme (REUTERS)Premium
Google announces new bug bounty programme (REUTERS)

Technology giant Google has launched a new bug bounty programme where it will award up to $31,337 (nearly 25 lakh) to researchers who spot vulnerabilities in the company's Open Source projects. The newly announced Vulnerability Reward Program (VRP) will focus on Google software and repository settings like GitHub actions, application configurations, and access control rules.

Depending on the severity of the vulnerability and the project's importance, rewards will range from $100 to $31,337. "The top awards will go to vulnerabilities found in the most sensitive projects: Bazel, Angular, Golang, Protocol buffers, and Fuchsia," Google said.

The larger amounts will also go to unusual or particularly interesting vulnerabilities, "so creativity is encouraged," said Google while launching its Open Source Software Vulnerability Rewards Programme (OSS VRP).

As the maintainer of major projects such as Golang, Angular, and Fuchsia, Google is among the largest contributors and users of open source in the world.

Last year, Google saw a 650 per cent year-over-year increase in attacks targeting the open source supply chain.

With the addition of Google's own vulnerability reward programme (VRP), researchers can now be rewarded for finding bugs that could potentially impact the entire open source ecosystem.

The original VRP programme was one of the first in the world and is now approaching its 12th anniversary.

"Over time, our VRP lineup has expanded to include programmes focused on Chrome, Android, and other areas. Collectively, these programs have rewarded more than 13,000 submissions, totalling over $38 million paid," Google said in a statement late on Tuesday.

Google said its OSS VRP is part of "our $10 billion commitment to improving cybersecurity, including securing the supply chain against these types of attacks for both Google's users and open source consumers worldwide".

(With inputs from IANS)

Unlock a world of Benefits! From insightful newsletters to real-time stock tracking, breaking news and a personalized newsfeed – it's all here, just a click away! Login Now!

Catch all the Technology News and Updates on Live Mint. Download The Mint News App to get Daily Market Updates & Live Business News.
More Less
Published: 31 Aug 2022, 06:26 PM IST
Next Story footLogo
Recommended For You
Switch to the Mint app for fast and personalized news - Get App