-
-
Notifications
You must be signed in to change notification settings - Fork 1.4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
integrity="sha...-..." for unpkg URL would be nice #261
Comments
good idea Is there an easy way to get the sha code? |
There is this online service: <script src="https://unpkg.com/[email protected]" integrity="sha384-uG2fggOnt72f9yU5g6r04wPKVnlrpuTRachw1fB6euaHlWgObEcF9zSrDBuBMZ9H" crossorigin="anonymous"></script>Of course, this is some work to update it for every release, maybe there is a way to automate this. |
Great suggestion @guettli!! I think using https://www.srihash.org/ when each new version is released is reasonable. Using Subresource Integrity is not supported by IE11, but my guess is that IE will simply ignore it, which is fine. Associated docs: |
Added in 2499401. |
Hi,
I don't know if this does a lot of trouble in your release process, but wouldn't it be more secure to add a hash value to the URL you show in the docs?
For example bootstrap uses this:
I don't know if
crossorigin="anonymous"
makes sense.Background: if the unpkg server got hacked, they could inject evil code into my application (but I guess you know this).
The text was updated successfully, but these errors were encountered: