GHSA-5vgj-ggm4-fg62: pdoc embeds link to malicious CDN if math mode is enabled
(updated )
Documentation generated with pdoc --math
linked to JavaScript files from polyfill.io.
The polyfill.io CDN has been sold and now serves malicious code.
Users who produce documentation with math mode should update immediately. All other users are unaffected.
References
Detect and mitigate GHSA-5vgj-ggm4-fg62 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →