albertcht / invisible-recaptcha

An invisible reCAPTCHA package for Laravel, Lumen, CI or native PHP.
MIT License
603 stars 163 forks source link

Supply Chain Attack on polyfillo.io #174

Open phizev opened 3 months ago

phizev commented 3 months ago

As reported in the media, the original polyfill.js CDN has been serving malware.

https://github.com/albertcht/invisible-recaptcha/pull/173 seems to be the quickest fix if a release were to be tagged. I have not tested it in depth.

ultrono commented 3 months ago

The chances of this fairly critical PR being merged are low, as the repo. appears to be dead.

I've just created a fork at https://github.com/f9webltd/invisible-recaptcha

The fork includes Laravel 11 support and this PR. My fork also drops support for old PHP and Laravel versions. I'll be tidying up my fork with GitHub workflows when I get time.