Pro tip if you are a startup and want free security advice. Just sign up for all the bounty sites and for every single bounty just tell the submitter that it is a duplicate bug and pay them nothing, then hot patch it immediately and when they get suspicious tell them that their bug report had absolutely nothing to do with the timing of your patch. I know there are companies that do this because I have had it happen t…
just tell the submitter that it is a duplicate
Or simply close it immediately with a nonsensical message unrelated to the problem report and then immediately change the code. (This happened to me last month.)