4 ms·
For most JS served by CDN, you can (and should) use Subresource Integrity to verify the content. At least the last time I was involved in an AMP project, Google
by donaltroddyn 6y ago
For most JS served by CDN, you can (and should) use Subresource Integrity to verify the content. At least the last time I was involved in an AMP project, Google considered AMP to be an "evergreen" project and did not allow publishers to lock in to a specific version.
- gregable 6y agoLong term versions are now supported, so publishers can lock in a specific version. Publisher hosted copies are in the pipeline, as I referenced in the parent comment. My choice of verbiage was a bit confusing it appears.
- donaltroddyn 6y agoI don't think it's your wording that's confusing. You are contradicting the AMP documentation. AMP's documentation seems to indicate that the LTS is stable only for one month (new features released via the same URL each month), and so is not compatible with SRI (see https://github.com/ampproject/amphtml/blob/master/contributing/lts-release.md https://github.com/ampproject/amphtml/blob/master/contributi...) You can specify a version (ie, https://cdn.ampproject.org/rtv/somenum/v0.js https://cdn.ampproject.org/rtv/somenum/v0.js), but the AMP validator complains about that.