Skip to content

Archive

Subresource Integrity

7 articles
Cybersecurity 23 Sep 2026 6 min read

Subresource Integrity Binds External Assets to Cryptographic Digests

Subresource Integrity Binds External Assets to Cryptographic Digests A web page can load JavaScript and CSS from an origin outside its own deployment boundary. That arrangement is convenient for shared packages and content delivery networks, but it also delegates part of the page’s execution or presentation path to the server that returns those resources. Subresource Integrity (SRI) adds a byte-level constraint to that dependency. The page supplies one or more cryptographic digests in an integrity attribute. A supporting browser fetches the resource, computes a digest with the declared algorithm, and accepts the response only when the bytes satisfy the integrity metadata.

Cybersecurity 22 Sep 2026 6 min read

Subresource Integrity Pins External Resources to Expected Bytes

Subresource Integrity Pins External Resources to Expected Bytes Loading a script or stylesheet from another host creates a direct dependency on the bytes that host returns. TLS protects the connection in transit, but it does not state that the response is the exact object the page operator intended to execute or apply. Subresource Integrity (SRI) adds that byte-level condition. An HTML element can carry integrity metadata containing one or more cryptographic digests. A supporting browser fetches the resource, computes the relevant digest, and uses the response only when the result satisfies the metadata.

Cybersecurity 22 Sep 2026 7 min read

Subresource Integrity Pins Browser-Loaded Assets to Approved Bytes

Subresource Integrity Pins Browser-Loaded Assets to Approved Bytes A web page can load executable code from infrastructure outside the application’s deployment boundary. A <script> URL may point to a CDN, a package distribution endpoint, or another origin operated under a separate release process. TLS protects the connection to that endpoint, but a valid HTTPS response can still contain bytes different from the version the page author intended to run. Subresource Integrity, commonly shortened to SRI, adds a content check at the browser. The document carries cryptographic digest metadata for a resource. After fetching the resource, the browser computes the applicable digest and compares it with the metadata before accepting the resource for the protected use.

Cybersecurity 20 Sep 2026 5 min read

Subresource Integrity Pins Browser Execution to Expected Bytes

Subresource Integrity Pins Browser Execution to Expected Bytes A web page can fetch JavaScript and stylesheets from infrastructure outside the application’s deployment boundary. A CDN improves distribution, but the browser normally treats the response from the referenced URL as the resource the page requested. If that response changes unexpectedly, transport security alone does not tell the browser that the bytes differ from the version selected by the application operator. Subresource Integrity (SRI) adds a content check to that load. The page carries cryptographic metadata for an expected representation. A supporting browser hashes the fetched resource and accepts it only when the result satisfies the declared integrity metadata.

Cybersecurity 15 Sep 2026 7 min read

Subresource Integrity Pins External Assets to Expected Bytes

Subresource Integrity Pins External Assets to Expected Bytes A web page can keep all of its application code under careful review and still execute JavaScript delivered from infrastructure outside its control. Analytics libraries, UI frameworks, payment components, and other dependencies are often fetched from a content delivery network. If that remote response changes, the browser normally has no basis for deciding whether the new bytes are an approved release or an unexpected substitution.

Cybersecurity 14 Sep 2026 6 min read

Subresource Integrity Pins Browser Dependencies to Expected Bytes

Subresource Integrity Pins Browser Dependencies to Expected Bytes A production page can contain no application-side injection flaw and still execute hostile JavaScript if a trusted external asset changes underneath it. The script URL may be correct, TLS may be valid, and the browser may have reached the intended host. None of those facts establish that the returned file is the exact artifact the site operator approved. Subresource Integrity, commonly shortened to SRI, adds that missing assertion for selected browser-loaded scripts and stylesheets. An integrity attribute carries one or more cryptographic digest values. After fetching the resource, the browser computes the digest of the representation used for the integrity check and refuses to apply or execute it when no supported digest matches.

Cybersecurity 10 Sep 2026 9 min read

Pin Third-Party Browser Assets with Subresource Integrity

Loading JavaScript directly from another organisation’s server creates a security dependency that is easy to overlook. Your page may contain only a short <script> tag, but the downloaded file executes with the privileges that your site gives that script. If the file at that URL changes unexpectedly, your users can receive code you never reviewed or deployed. Subresource Integrity (SRI) gives the browser an expected cryptographic hash for a fetched resource. The browser hashes the bytes it receives and loads the resource only when the result matches the declared value. That turns “load whatever this URL serves” into “load the specific content I approved from this URL.”