Follow the latest coverage, related explainers and connected technology stories.
Google has temporarily suspended the intake of product vulnerability reports under the OSS VRP after a large influx of automated reports, saying that most of them were invalid. Supply-chain reports and some reports through other bug bounty programs will continue to be accepted, with the company set to announce program changes in the first quarter of 2027.
A JetBrains article examines five areas of risk threatening government software compliance, from data protection and supply chain integrity to auditing and continuity. It calls for moving controls from delayed manual review to traceable automated checks within the development lifecycle and CI/CD pipelines.