eleven_ty’s avatareleven_ty’s Twitter Archive—№ 6,264

  1. Responsible disclosure: the ua-parser-js package used by browser-sync was compromised. New installs are safe but you may want to npm install browser-sync on any existing projects to make sure you don’t have a compromised version locally. github.com/11ty/eleventy/pull/2054#issuecomment-951990320