Highlights
Credential Leak: 1 prior fix. Scrutinize any change in this area.
Actions: most-fixed (1 issue). Treat as high-risk during review.
1 high-severity fix in this history; regressions here are high-impact.
Recurring patterns
The bug types that recur here, drawn from past fixes, not open vulnerabilities.
Deserialization: Attackers can exploit deserialization mishandling in class utilities to achieve arbitrary code execution, which has been leveraged in active exploitation.
Insecure TLS: Outdated or untrusted root CAs remaining in the bundled certificate store can allow Man-in-the-Middle (MitM) attackers to intercept and decrypt secure HTTP requests made by the library.
Credential Leak: GitHub Actions workflows that persist Git credentials on disk risk exposing sensitive tokens to downstream actions or in published artifacts.