cdn.polyfill.io (https://polyfill.io/v3/) has some issue #11757
Closed
tenchiwang2
started this conversation in
General
Replies: 1 comment
-
This was removed in #11741 and will be deployed with the next release |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
i am sorry.
i mainly want to remove the description of https://polyfill.io/v3/
in
https://github.com/remix-run/react-router/blob/main/packages/react-router-dom/index.tsx#L1469
because this narrative is still there after compilation.
///================ You can refer to the following
This website was created to bring awareness to a major JavaScript supply chain vulnerability with a well known and broadly used JavaScript file hosted on the polyfill.io domain name.
As of February 24, 2024, cdn.polyfill.io, the domain hosting the polyfill.io JavaScript library, has been acquired by a Chinese company named Funnull. Polyfill.io is a widely used JavaScript library integrated into many of the world's most well known web applications. All polyfill.io traffic is now pointing to the Baishan Cloud CDN (https://www.baishancloud.com/).
There are many risks associated with allowing an unknown foreign entity to manage and serve JavaScript within your web application. They can quietly observe user traffic, and if malicious intent were taken, they can potentially steal usernames, passwords and credit card information directly as users enter the information in the web browser.
has some discuss can see down link.
https://blog.cloudflare.com/polyfill-io-now-available-on-cdnjs-reduce-your-supply-chain-risk?utm_campaign=cf_blog&utm_content=20240229&utm_medium=organic_social&utm_source=twitter
https://community.fastly.com/t/new-options-for-polyfill-io-users/2540
polyfillpolyfill/polyfill-service#2873
https://polykill.io/
Beta Was this translation helpful? Give feedback.
All reactions