Announcement

Collapse
No announcement yet.
X
  • Filter
  • Time
Clear All
new posts

    polyfill.js supply chain attack

    Hi Isomorphic,

    Can you please confirm the SmartGWT libraries are not impacted by the following.

    https://sansec.io/research/polyfill-supply-chain-attack

    Thank you


    #2
    This library is not one we use, and does not appear to be a dependency that appears anywhere in our npm dependency tree (which you probably aren't using anyway).

    Since the library is not part of our framework, it would not appear in your application, so you should not be vulnerable unless you separately used this library.

    Comment


      #3
      Thank you for the update.

      Comment

      Working...
      X