w3ctag / polyfills

Finding on polyfills
https://w3ctag.github.io/polyfills
18 stars 6 forks source link

Remove reference to polyfill.io #37

Closed triblondon closed 7 months ago

triblondon commented 7 months ago

The owner of the polyfill.io domain appears to have changed. The website for the project links to a GitHub repo owned by an individual, but there's no information about governance or any indication that the hosted service is still operated by that individual. The TAG should no longer link to this and should consider it a security risk.

The finding also links to CDNJS, which could be retained, and does seem to have more transparent governance, but overall it seems worth the TAG not endorsing any one site.