@sentry/react-native 8.26.0 appears to be a healthy, mature dependency. It has been maintained since 2019 with 336 releases, 56 releases in the last 12 months, and a latest release published on the assessment date; the linked organization-owned repository is active, unarchived, and shows 467 commits from 19 active maintainers over three months. The package includes an MIT license, extensive TypeScript declarations, tests, a README, and no install lifecycle scripts, while the repository provides releases, tests, security scanning, and a security policy. The main reservations are absent build provenance attestations and broad GitHub Actions permission configuration, including three workflows with top-level write permissions; these reduce supply-chain transparency and workflow hardening but are not evidence that the package is unsafe to depend on.
88%
Total Score
100
100
100
80
50
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10992 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @sentry/react-native is vulnerable to Relative Path Traversal in versions 1.0.0 - 8.9.2. | 1.0.0 - 8.9.2 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
@sentry/cli Version 3.7.0 | — | — |
@sentry/core Version 10.74.0 | — | — |
@sentry/react Version 10.74.0 | — | — |
@sentry/browser Version 10.74.0 | — | — |
@sentry/bundler-plugins Version 10.74.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.