4 ms·
You can specify a hash for your CDN hosted dependencies so they aren't changed unexpectedly: https://developer.mozilla.org/en-US/docs/Web/Security/Subresource_I
by qbasic_forever 3y ago
You can specify a hash for your CDN hosted dependencies so they aren't changed unexpectedly: https://developer.mozilla.org/en-US/docs/Web/Security/Subresource_Integrity https://developer.mozilla.org/en-US/docs/Web/Security/Subres...
There's zero reason not to trust a CDN if you're using integrity checks. It's just a host on the internet sending you bits.
- cormacrelf 3y agoIt almost but not quite goes without saying, but if the import is (for example) the YouTube embed client script, you should not put an integrity check on it. Because you expect YouTube to put out a new client script from time to time. If there’s an integrity check based on an old version of the script, it will just break your page.
- easrng 3y agoI don't think you can use SRI with imports?
- croes 3y agoSeems like that's not possible for import maps https://news.ycombinator.com/item?id=35801366 https://news.ycombinator.com/item?id=35801366
- toastal 3y agoYou're passing IP addresses and who knows what else to these CDN providers by using them. Add-ons like Decentraleyes were created because this leaks info, SRI or not.