polyfill.io library is no longer considered safe to use

Created on 24 June 2024, about 1 year ago

Problem/Motivation

The polyfill.io library has been sold to a Chinese company named Funnull that is not considered trustworthy. We believe this poses a grave security threat and the library is now considered unsafe.

https://twitter.com/triblondon/status/1761852117579427975

There is also evidence https://github.com/polyfillpolyfill/polyfill-service/issues/2873#issueco... that polyfill.io is used to serve malicious code.

Proposed resolution

There are some mentions in the module about polyfill.io for example in https://git.drupalcode.org/project/dsfr/-/blob/2.1.x/dist/dsfr/dsfr.nomo.... It would be good to replace it with a safe option from Fastly or Cloudflare. These seem to be in some dist files which need to be checked.

https://community.fastly.com/t/new-options-for-polyfill-io-users/2540
https://blog.cloudflare.com/polyfill-io-now-available-on-cdnjs-reduce-yo...

๐Ÿ“Œ Task
Status

Active

Version

2.1

Component

Code

Created by

๐Ÿ‡ซ๐Ÿ‡ฎFinland heikkiy Oulu

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

Production build 0.71.5 2024