
vue-i18n master の PR #2470 をrevertした。CVE-2025-53892 backportでコード自体に悪意があるコードは無いんだけど、contributorのGitHubアカウントがrename→ 削除っていう感じでsupply chain attackの前兆パターンっぽいので未知のケースの可能性もあるから念のため。ここ昨今のOSS界隈怖すぎる... 修正は自分で再適用します。 https://github.com/intlify/vue-i18n/pull/2485
Post summary
The author notes a revert of a backported CVE‑2025‑53892, expresses concern about a potential supply‑chain hint, and states that they will reapply the fix via a new pull request.
