| ▲ | da_grift_shift 20 hours ago | ||||||||||||||||||||||
>Also not much excuse for xss these days. XSS is not dead, and the web platforms mitigations (setHTML, Trusted Types) are not a panacea. CSP helps but is often configured poorly. So, this kind of widespread XSS in a vulnerable third party component is indeed concerning. For another example, there have been two reflected XSS vulns found in Anubis this year, putting any website that deploys it and doesn't patch at risk of JS execution on their origin. Audit your third-party dependencies! https://github.com/TecharoHQ/anubis/security/advisories/GHSA... https://github.com/TecharoHQ/anubis/security/advisories/GHSA... | |||||||||||||||||||||||
| ▲ | azemetre 20 hours ago | parent [-] | ||||||||||||||||||||||
Is it really fair to compare an open source project that desperately wants only $60k a year to hire a dev with companies that have collectively raised over billions of dollars in funding? | |||||||||||||||||||||||
| |||||||||||||||||||||||