GM does have a Hackerone account:
https://hackerone.com/gm
Though, all the bugs are hidden due to disclosure lockdown by I think GM. You have to have an account on Hackerone to see the actual bugs and even then, I don't think you can see other bugs, just your own and its progress during review by GM.
Honestly, I'd pull the OnStar fuse if you're really concerned. One thing I recall is most new cars are fly-by-wire systems so control of the CAN bus can disable your steerage, acceleration, even your brake pedal. However, I think the one thing that is read-only by CAN bus is the EPB. This is why I think in the manual you're supposed to pull up on the EPB switch and HOLD it up for emergency braking should the Bolt decide to accelerate on its own. Nothing can control EPB except the switch and directly pressing on the "release" button on teach EPB module (I forget where I read this, but it was during my research about how to disable the EPB should I need to tow the Gen 2 Volt which I assume has similar EPB as Bolt).