google / google/learned_optimization
Clarification requested: discrepancy between the "not an official Google product" disclaimer and the apparent eligibility/scope under Google OSS VRP (Bug Bounty)
- Dominant language
- Python
- Stars
- 814
- Forks
- 73
- Avg merge
- 9h 40m
- Merged PRs (30d)
- 2
Description
Hello,
I would like to raise a documentation and communication concern, and request clarification regarding the security posture and reporting scope for this repository.
The **google/learned_optimization** README explicitly states that this project:
* ***learned\_optimization* is not an official Google product.**
At the same time, Google’s **Open Source Software Vulnerability Reward Program** publicly states that it covers the latest versions of open source software stored in public repositories of Google-owned GitHub organizations.
From an external researcher or user perspective, this creates a potentially confusing situation: the repository is presented as *not being an officially supported Google product*, while at the same time it appears to fall under a Google vulnerability reward scope due to its presence under the **google** GitHub organization.
This ambiguity may matter in at least three ways:
1. The actual level of support and maintenance users should expect;
2. The expected vulnerability handling and disclosure pathway;
3. The security and trust expectations associated with software published under a Google-owned organization.
Because of that, I would appreciate explicit clarification on the following points:
1. Is **google/learned_optimization** actually in scope for any Google vulnerability reward program or is out-of-scope (OOS)?
2. If so, does that coverage exist solely because the repository belongs to a Google-owned GitHub organization, or is there also a project-specific commitment regarding vulnerability handling?
3. Would it make sense to reflect that status more clearly in the README or security documentation, so that the "not officially supported Google product" disclaimer is not interpreted in a way that conflicts with an apparent VRP eligibility?
The purpose of this issue is not to challenge the existence of the repository or the program, but to request clearer documentation so that researchers and users can better understand the project’s actual status, support expectations, and eligibility as scope for bug bounty hunting.
Thank you.
Contributor guide
Assessment
This issue has not been assessed yet.