Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

安全漏洞 #6668

Closed
canyueduhong opened this issue Jul 8, 2024 · 7 comments
Closed

安全漏洞 #6668

canyueduhong opened this issue Jul 8, 2024 · 7 comments
Labels

Comments

@canyueduhong
Copy link

Version of antd-mobile

5.37.1

Operating system and its version

Others

Browser and its version

服务器插件漏洞

Sandbox to reproduce

No response

What happened?

我们的安全团队扫描发现了一个关于 intersection-observer 0.12.2插件存在木马的问题。然而,根据我们查看 intersection-observer 的官方信息,并没有发现可用的更新版本进行升级。请问是否有替换这个插件的方案,或者其他的解决方法?

期待您的回复。

Relevant log output

No response

@zombieJ
Copy link
Member

zombieJ commented Jul 8, 2024

有相关的报告么?

@canyueduhong
Copy link
Author

image

@zombieJ
Copy link
Member

zombieJ commented Jul 9, 2024

看了一下没有相关的报告,推测是 test.html 误触发了 polyfill.io 安全警告,可以再确认一下:

ref: https://security.snyk.io/package/npm/intersection-observer

@canyueduhong
Copy link
Author

你的意思是说/node_modules/intersection-observer-test.html文件里的https://cdn.polyfill.io/v2/polyfill.min.js?features=es5,getComputedStyle链接误触发了安全警告导致的吗?
可是我们的安全团队不认可该解释,麻烦问下假如我尝试在package.lock.json中去掉这个插件,会导致ant-mobile除了ahooks相关的组建失效,或者其它影响吗?

@canyueduhong
Copy link
Author

搜索了下居然能搜到相关新闻(手动捂脸哭)😭
https://baijiahao.baidu.com/s?id=1803720749750686030&wfr=spider&for=pc

@zombieJ
Copy link
Member

zombieJ commented Jul 9, 2024

可以考虑自己发一个包,然后 npm 里 override 成自己的试试。这个包是 google 的,本身是没啥问题的。 issue 这边就先关了哈~

@zombieJ zombieJ closed this as completed Jul 9, 2024
@canyueduhong
Copy link
Author

好的,感谢

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants