Open
Description
opened on Jun 26, 2024
Should we discuss the situation around polyfill.io?
Background:
https://blog.cloudflare.com/polyfill-io-now-available-on-cdnjs-reduce-your-supply-chain-risk
Potential npm packages which inject this code in runtime:
- https://github.com/search?q=polyfill.io+language%3ATypeScript+&type=code
- https://github.com/search?q=polyfill.io+language%3AJavaScript+&type=code
What I personally think: maybe we should try to suspend from Node.js community side new owners at GitHub as potentially malicious distributor.
It looks like the new owners are deleting all issues related to the situation:
Metadata
Assignees
Labels
No labels
Activity