If we discover a bug in a plugin registered with us, we will provide a verified bug report to the developer so that they can get it fixed ASAP. By providing a verified bug report, the developer doesn't have to spend time trying to reproduce reports of issues that may or may not be actual bugs.
If we discover a security issue in a plugin, we contact the plugin developer immediately so that it can be addressed.