okikio/bundlejs

[SECURITY VULNERABILITY] In your codebase is a reference of the cdn com polyfill com io service

Closed this issue · 1 comments

# Link: <https://cdn.polyfill.io/v3/polyfill.min.js?features=requestIdleCallback>; rel=preload; as=script

This file is using the cdn.polyfill.io service which is known for injecting malicious code

Please use the cloudflare polyfill service

https://x.com/WeldPond/status/1805973940642119900

Thanks for the find, I stopped using polyfill.io a couple years ago I just commented it out at the time, but I guess I hadn't removed the old comments. I've now removed all references to polyfill.io