Polyfill as an example of Supply Chain attack
Nobody has claimed this yet.
- Dominant language
- HTML
- Stars
- 6.1k
- Forks
- 1.1k
- PR merge metrics
- No merged PRs in 30d
Description
Hi there,
I was thinking, for the next edition of the OWASP (2025?) a good example of Supply Chain attack could be the polyfill.io incident.
It's a good example of why not to trust 3rd party CDNs, especially considering how widespread it got, affecting over 100k websites across the world.
And it was the result of a popular domain expiring and being acquired by a malicious party.
A good place to place this would be in the "Software and Data Integrity Failures" chapter, probably together with (or in lieu of) the SolarWinds Orion attack:
https://github.com/OWASP/Top10/blob/90859c5178d4208e1ebed5b481898b575b4b98ec/2021/docs/en/A08_2021-Software_and_Data_Integrity_Failures.md?plain=1#L70-L71
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Review docs/en/A08_2021-Software_and_Data_Integrity_Failures.md, especially the section linked in the issue, and compare the existing SolarWinds Orion example with the proposed polyfill.io incident. Done means the chapter reflects a decided example choice and includes the relevant supply-chain incident context.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation, security
- Issue type
- Documentation
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 38/100