Skip to content

Dependency on compromised polyfill.js CDN via albertcht/invisible-recaptcha #191

@phizev

Description

@phizev

As reported in the media, the original polyfill.js CDN has been serving malware. While this Craft plugin does not directly have a dependency on poilyfill.js, a dependency of it does, namely albertcht/invisible-recaptcha.

I've filed a PR albertcht/invisible-recaptcha#173, and opened an issue albertcht/invisible-recaptcha#174 with the downstream project.

Unfortunately the project does not seem to be actively maintained, and has not had any PR's merged since 2022.

I'm not sure on the best path to resolving this issue, though the quickest might be to switch to a fork of albertcht/invisible-recaptcha with the polyfill.js either removed, or updated to an alternative.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions