Should I be concerned that Recognize indirectly refers to JS from polyfill.io? (Supply-chain attack) #1155
|
Grepping through my app installation of nextcloud, I see the following: Apparently polyfill.io's domain changed ownership, and the new owners are injecting malware to anyone importing their repos. I have absolutely no expertise in JS, nor how Nextcloud apps may or may not depend on JS. Is this a potential attack vector on the Recognize app or Nextcloud in general? |
Answered by
marcelklehr
Jul 5, 2024
Replies: 1 comment 1 reply
|
Thank you for raising this issue. Luckily this is not an attack vector on the recognize app or Nextcloud in general. The mentioned polyfill.io URL is only part of the build script for the documentation of a dependency of recognize. |
1 reply
Answer selected by
Russtopia
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Thank you for raising this issue. Luckily this is not an attack vector on the recognize app or Nextcloud in general. The mentioned polyfill.io URL is only part of the build script for the documentation of a dependency of recognize.