Worth grepping your source code for "polyfill.io" and taking urgent measures to remove that code if you're linking it into your site - the domain name apparently now intermittently serves malicious JavaScript

My notes here: simonwillison.net/2024/Jun/25/ - or read this article sansec.io/research/polyfill-su

@simon I'm happy in the knowledge that my source code never downloads code at run-time.

When we build, we know what we build, and our binaries are signed and all that.

Sign in to participate in the conversation
Qoto Mastodon

QOTO: Question Others to Teach Ourselves
An inclusive, Academic Freedom, instance
All cultures welcome.
Hate speech and harassment strictly forbidden.