[Security] 后面是否考虑替换存在安全问题的intersection-observer依赖?
Open
pr welcomed
- Dominant language
- TypeScript
- Stars
- 15k
- Forks
- 2.8k
- Avg merge
- 15h 7m
- Merged PRs (30d)
- 2
Description
Polyfill.io在引用时会执行额外的JS指令而造成供应链攻击,原本位于github上的专案GitHub也已添加告警字样。hooks依赖的intersection-observer intersection-observer-test.html文件中有引入`
Contributor guide
Research direction
Start with intersection-observer-test.html and inspect how the intersection-observer dependency references polyfill.io. Confirm the scope of the insecure external script and identify whether the dependency can be replaced or another remediation is needed; done means the security concern is addressed without that unsafe reference.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- react, typescript
- Domain
- frontend, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100