Subresource Integrity Pins External Resources to Expected Bytes
Subresource Integrity Pins External Resources to Expected Bytes Loading a script or stylesheet from another host creates a direct dependency on the bytes that host returns. TLS protects the connection in transit, but it does not state that the response is the exact object the page operator intended to execute or apply. Subresource Integrity (SRI) adds that byte-level condition. An HTML element can carry integrity metadata containing one or more cryptographic digests. A supporting browser fetches the resource, computes the relevant digest, and uses the response only when the result satisfies the metadata.