Skip to content

Serving JS files from /vendor is insecure #275

Closed
@thisismydesign

Description

@thisismydesign

I think nothing is stopping me from creating a commit in a project that says 'Update react' and making arbitrary changes to vendor/javascript/react.js. The change is impossible to review and AFAICT nothing is checking the integrity of this file. At least I could modify the file in my project and the modified file was simply served.

Related: #122 and #199

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions