@gouvfr/dsfr is vulnerable to Malicious Code
100
Critical Risk
Affected versions of @gouvfr/dsfr use polyfill[.]io, which is taken over by attackers and serves malicious code.
You are affected if you are using a version that falls within the vulnerable range.
@gouvfr/dsfr is vulnerable to Malicious Code in versions 0.1.0 - 1.12.1.
Upgrade the @gouvfr/dsfr library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant