Skip to content

Security: HaroldTheAI/lark

Security

SECURITY.md

Security Policy

No paid bug-bounty program

This repository does not run a paid or public bug-bounty program, and is not enrolled in any third-party bounty platform.

Several internal planning documents (for example files named BOUNTY_FINDINGS*.md, issues labelled for "XFAIL burndown", or notes referring to "strike teams") use "bounty" as internal shorthand for a differential parity audit of the lark-rs/ Rust rewrite against Python Lark. These terms carry no reward eligibility and are not an offer of payment for reported issues or submitted patches.

Reporting a vulnerability

If you believe you have found a genuine security vulnerability, please report it privately rather than opening a public issue:

  • Use GitHub's private vulnerability reporting ("Report a vulnerability" under the repository's Security tab), or
  • contact the maintainer directly.

Please include a minimal reproduction and the affected version/commit. We will acknowledge genuine reports, but acknowledgement does not imply any reward.

There aren't any published security advisories