I'd like to be notified about weird vulnerabilities in JavaScript libraries for the release branch as well. It's double important since the release branch ships particular pinned version of *all* dependencies.
Make sure that the released version is also fine. Run this test every time a push is made into the release branch as well as on schedule.