quarto: apply patch removing the usage of polyfill.io in the templates

When outputting HTML content with MathJax content a JS library is
provided by `cdn.polyfill.io` which is now considered to be a bad
actor.

https://sansec.io/research/polyfill-supply-chain-attack
This commit is contained in:
Thomas Gerbet
2024-06-30 13:39:09 +02:00
parent ed07793ec7
commit be27a92e35

View File

@@ -5,6 +5,7 @@
, esbuild
, deno
, fetchurl
, fetchpatch
, dart-sass
, rWrapper
, rPackages
@@ -29,6 +30,16 @@ stdenv.mkDerivation (final: {
makeWrapper
];
patches = [
(fetchpatch {
name = "drop-usage-known-bad-actor-cdn.patch";
url = "https://github.com/quarto-dev/quarto-cli/commit/9f02884fec462e16b82bdf0acc632246b2f40201.patch";
relative = "src/resources";
extraPrefix = "share/";
hash = "sha256-RUIaQCqi3fWn1UIxcMi6/6vh4ANuL44uOnC/bnsHT/k=";
})
];
postPatch = ''
# Compat for Deno >=1.26
substituteInPlace bin/quarto.js \