
Security-research lab reproducing CVE-2025-53104 (GHSA-432r-9455-7f9x): command injection in discussion-to-slack.yml of gluestack/gluestack-ui
Automated research artifact — not the upstream project.
This repository is a disposable lab built by an automated harness for a master's thesis at Université Laval on reproducing published GitHub Actions workflow vulnerabilities. It is a verbatim snapshot of
gluestack/gluestack-uiat commit46641d268259805ddf1f8f785051df756cdbd62a(2025-04-14), redistributed under that project's own licence, whose file is included unchanged in this snapshot.The upstream project is not involved, is never targeted, and the vulnerability studied here is already public. Every secret and variable in this repository is a randomly generated dummy value — no real credential is present. Action references and runner images are pinned to what they resolved to on 2025-04-14; see
pinning.mdin the harness output for every change made to the snapshot.Questions or objections: [email protected]
gluestack-ui is a library of copy-pasteable components & patterns crafted with Tailwind CSS (NativeWind).
gluestack-ui v2 offers customizable, beautifully designed components for your projects. Unlike traditional libraries, it's not a pre-packaged dependency. Choose the components you need and copy-paste them directly into your React, Next.js & React Native projects.
You can find detailed documentation for each component, including a list of props and examples, in https://gluestack.io/ui/docs website.
To get started with gluestack-ui v2, you must have an existing Next.js or Expo project. Then, simply run the following command:
npx gluestack-ui init
For detailed installation instructions, visit the gluestack-ui v2 installation guide.
JavaScript, React, React Native, Styled System
If you're migrating from gluestack-ui v1, we've got you covered with a detailed migration guide with codemod.
GeekyAnts is a team of React Native experts who love open-source and solving developer problems. We’ve been working on React Native since 2015 and have designed and built React Native apps for almost 200+ clients across the globe. Our clients include startups to big enterprises! Need help with your React Native app?
We welcome contributions to the gluestack-ui. If you have an idea for a new component or a bug fix, please read our contributing guide instructions on how to submit a pull request.
Licensed under the MIT License, Copyright © 2024 GeekyAnts. See LICENSE for more information.