facebook/fbjs

"ua-parser-js": "0.7.30" have a wrong

Closed this issue · 3 comments

Uncaught TypeError: e[r].toUpperCase is not a function

zpao commented

I'm sorry, is there something in this project that's causing your problem?

Hi! Regarding ua-parser-js, what about bumping to v1 in order to be safe? Malicious versions have been unpublished though
https://portswigger.net/daily-swig/popular-npm-package-ua-parser-js-poisoned-with-cryptomining-password-stealing-malware

zpao commented

1.0.0 was also hijacked so it's no more safe. I won't be bumping across major versions here without also bumping our major version.