Should I be concerned that Recognize indirectly refers to JS from polyfill.io? (Supply-chain attack) #1155
-
Grepping through my app installation of nextcloud, I see the following:
Apparently polyfill.io's domain changed ownership, and the new owners are injecting malware to anyone importing their repos. I have absolutely no expertise in JS, nor how Nextcloud apps may or may not depend on JS. Is this a potential attack vector on the Recognize app or Nextcloud in general? |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 1 reply
-
Thank you for raising this issue. Luckily this is not an attack vector on the recognize app or Nextcloud in general. The mentioned polyfill.io URL is only part of the build script for the documentation of a dependency of recognize. |
Beta Was this translation helpful? Give feedback.
Thank you for raising this issue. Luckily this is not an attack vector on the recognize app or Nextcloud in general. The mentioned polyfill.io URL is only part of the build script for the documentation of a dependency of recognize.