3 ms·
Except now you're making http calls to remote servers that could be compromised.
by runtime_terror 4mo ago
Except now you're making http calls to remote servers that could be compromised.
- phpdave11 4mo agoAs long as you embed it with an SRI integrity hash, you're safe, even if the remote server is compromised.
- bdcravens 4mo agoCan be mitigated, as the sibling comment points out, but even in the situation you described, the blast radius is reduced, especially for frontend libs.
- grugdev42 4mo agoThis is a solved problem. Use HTTPS and use the integrity attribute. https://developer.mozilla.org/en-US/docs/Web/HTML/Reference/Attributes/integrity https://developer.mozilla.org/en-US/docs/Web/HTML/Reference/... Also, what's more likely? Someone hacking jsDelivr/cdnjs OR some random NPM packages getting hacked?