Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security] 后面是否考虑替换存在安全问题的intersection-observer依赖? #2595

Open
achu19 opened this issue Jul 12, 2024 · 1 comment

Comments

@achu19
Copy link

achu19 commented Jul 12, 2024

Polyfill.io在引用时会执行额外的JS指令而造成供应链攻击,原本位于github上的专案GitHub也已添加告警字样。hooks依赖的intersection-observer intersection-observer-test.html文件中有引入<script src="https://polyfill.io/v3/polyfill.min.js,请问后面会更换依赖或采取别的方法修复该问题吗?

@crazylxr
Copy link
Collaborator

欢迎 PR

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants