Wow. I'd like to quote the final section "Interactions with the vendor". It's been my experience as a user as well, of my very numerous bug reports - not because it's buggier than others but because I'm quick posting them - most have been solved within a very reasonable amount of time (I always provide a reproducible test case, which helps).<p><i>From here on it's all a quote</i>:<p>"I’d like to specifically thank Hadi Hariri and the rest of the JetBrains team for their proactive response to my report. My email requesting a security contact was answered within an hour of my sending it, and the issue was resolved relatively quickly."<p>"They sent me a patchset against intellij-community and a binary build with their proposed solutions, and were receptive to my feedback when I mentioned potential issues."<p>"Lastly, even though Jetbrains doesn’t have a bug bounty program that I’m aware of, and I definitely wasn’t expecting anything, Jetbrains quite generously awarded a bounty of $50,000 for my report and help reviewing the patch. I’ve asked them to donate the bulk of this to the PyPy project to fund improved Python 3 support, fingers crossed for await/async support in PyPy :)."