Skip to content

Commit a86e378

Browse files
committed
Add warning about polyfill.io
1 parent 58cf5ae commit a86e378

File tree

1 file changed

+10
-0
lines changed

1 file changed

+10
-0
lines changed

web/start.rst

+10
Original file line numberDiff line numberDiff line change
@@ -208,6 +208,16 @@ version 3 to work with IE11, include the line
208208
before the script that loads MathJax. Support for IE11 is not
209209
guaranteed, and may be dropped in the future.
210210

211+
.. warning::
212+
213+
The original `polyfill` website was purchased by a Chinese company
214+
in 2024, and has been used to inject malware into pages that use
215+
it. You should **NOT** use the ``polyfill.io`` library any longer,
216+
and should either remove the reference entirely, or switch to a
217+
link like the one above. See `this post
218+
<https://sansec.io/research/polyfill-supply-chain-attack>`__ for
219+
more details.
220+
211221
-----
212222

213223

0 commit comments

Comments
 (0)