Security context

What an agent needs to avoid regressing past fixes and find the next vuln in this repo.

software-mansion/react-native-gesture-handler
main @ 571e3cc
1
Fixes
0
CVEs
HIGH
Peak severity
Highlights
Supply Chain Attack: 1 prior fix. Scrutinize any change in this area.
.github/workflows/publish-release.yml: most-fixed (1 issue). Treat as high-risk during review.
1 high-severity fix in this history; regressions here are high-impact.
Recurring patterns

The bug types that recur here, drawn from past fixes, not open vulnerabilities.

Supply Chain Attack: Using unpinned external actions from mutable references (like '@main') in high-privilege workflows allows upstream maintainers, or attackers who compromise the upstream repository, to execute arbitrary code within the release pipeline. This could lead to the leakage of NPM publishing secrets or the injection of malicious code into official releases.