Policy
No More Free-ish Bugs
there's a fresh conversation happening at the moment about this is an area where the distinction between a bug bounty program (cash or cash equivalent proactively offered to the public) and a vulnerability disclosure program (which can optionally offer a thankyou listing, swag, or some other non-financial gesture