You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
By default Deno allows importing sources from following hosts:
deno.land
esm.sh
jsr.io
cdn.jsdelivr.net
raw.githubusercontent.com
gist.githubusercontent.com
They however don't explain why these particular domains are fine, while others are not. What is the threat model here? Why gist.githubusercontent.com is fine, but some other random paste bin as not?
Activity
dsherret commentedon Nov 23, 2024
Thanks for the nudge. There's a cve we were holding off on publishing until a bit after 2.0 and we should publish that now. cc @bartlomieju