Supply chain attacks, React, and the death of “mix & match” development
Recently, a popular open source project called polyfill.js was taken over by a bad actor, who injected malicious code into the project. 100s of thousands of sites with CI (Continuous Integration) systems did their usual automated build & deploy cycle and the exploit is now all over the place. This is called a “supply chain attack” and you have to...