Most of the supply chain vulnerabilities I've seen published and talked about lately have been trying to do things like exfiltrate keys/secrets from developers, including ci.
So of you've got a pr open with the vulnerable package update on it then you've goofed. Even potentially without merging if you've not got ci set up very securely, which is probably more common than we'd like to admit
On my (lineage) phone I can press "emergency " instead of typing the pin, and then reveal emergency contacts and medical information I choose to put there (allergy's, medication etc)
I don't think I installed an app. I assume its a aosp feature.
More than once I've wondered if I can make something look like google fit to other apps, obviously would have to be on a degoogled rom, which limits its utility for a wider audience.
Most of the supply chain vulnerabilities I've seen published and talked about lately have been trying to do things like exfiltrate keys/secrets from developers, including ci.
So of you've got a pr open with the vulnerable package update on it then you've goofed. Even potentially without merging if you've not got ci set up very securely, which is probably more common than we'd like to admit