Skip to content

Should I be concerned that Recognize indirectly refers to JS from polyfill.io? (Supply-chain attack) #1155

Answered by marcelklehr
Russtopia asked this question in Q&A
Discussion options

You must be logged in to vote

Thank you for raising this issue. Luckily this is not an attack vector on the recognize app or Nextcloud in general. The mentioned polyfill.io URL is only part of the build script for the documentation of a dependency of recognize.

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@Russtopia
Comment options

Answer selected by Russtopia
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants