FRCSoftware updates on a rolling basis, where we use CI/CD to deploy every commit. If you think you've identified a vulnerability, please ensure that you've checked against the latest version of the site and various infrastructure.
If you find a vulnerability, please contact us immediately at security@frcsoftware.org. We'll notify you that we've received the report, and again when we've resolved it. We do not have a bug bounty program, and since this is an open-source project, we are not currently offering any rewards for disclosures.