Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> New version of that CDN'ed Javascript library does something you don't expect? Your fault.

That's what the "integrity" field is for. If the CDN tries to change the file surreptitiously, it'll have a different checksum and the browser won't run it.



True, that is a step in the right direction. Ideally that would work for any resource - fonts, images, etc.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: