This repository does not run a paid or public bug-bounty program, and is not enrolled in any third-party bounty platform.
Several internal planning documents (for example files named
BOUNTY_FINDINGS*.md, issues labelled for "XFAIL burndown", or notes referring to
"strike teams") use "bounty" as internal shorthand for a differential parity
audit of the lark-rs/ Rust rewrite against Python Lark. These terms carry no
reward eligibility and are not an offer of payment for reported issues or submitted
patches.
If you believe you have found a genuine security vulnerability, please report it privately rather than opening a public issue:
- Use GitHub's private vulnerability reporting ("Report a vulnerability" under the repository's Security tab), or
- contact the maintainer directly.
Please include a minimal reproduction and the affected version/commit. We will acknowledge genuine reports, but acknowledgement does not imply any reward.