We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent a1b0703 commit ceda46eCopy full SHA for ceda46e
javascript/ql/src/Security/CWE-830/PolyfillIOCompromisedScript.qhelp
@@ -6,13 +6,13 @@
6
<p>
7
Polyfill.io was a popular JavaScript polyflll Content Delivery Network (CDN),
8
used to support new web browser standards on older browsers.
9
- <p>
+ </p>
10
11
12
In February 2024 the domain was sold, and in June 2024 it was widely publicised that the domain
13
had been used to serve malicious scripts. It was taken down later in that month, leaving a window
14
where sites that used the service could have been compromised.
15
16
17
18
Including a resource from an untrusted source or using an untrusted channel may
0 commit comments