HTML <script> integrity Attribute
Link to a CDN, using both the integrity and crossorigin atributes:
Definition and Usage
integrity attribute allows a browser to check the fetched script to ensure that the code is
never loaded if the source has been manipulated.
Subresource Integrity (SRI) is a W3C specification that allows web developers to ensure that resources hosted on third-party servers have not been altered. Use of SRI is recommended!
When using SRI, the webpage holds the hash and the server holds the file (the
.js file in this case). The browser downloads the file, then checks it, to make
sure that it is a match with the hash in the
integrity attribute. If it matches,
the file is used, and if not, the file is blocked.
You can use an online SRI hash generator to generate integrity hashes: SRI Hash Generator
The numbers in the table specify the first browser version that fully supports the attribute.
|The file hashing value of the external script file
❮ HTML <script> tag