Subresource Integrity Pins Browser-Loaded Assets to Approved Bytes
Subresource Integrity Pins Browser-Loaded Assets to Approved Bytes A web page can load executable code from infrastructure outside the application’s deployment boundary. A <script> URL may point to a CDN, a package distribution endpoint, or another origin operated under a separate release process. TLS protects the connection to that endpoint, but a valid HTTPS response can still contain bytes different from the version the page author intended to run. Subresource Integrity, commonly shortened to SRI, adds a content check at the browser. The document carries cryptographic digest metadata for a resource. After fetching the resource, the browser computes the applicable digest and compares it with the metadata before accepting the resource for the protected use.