Skip to content

Archive

Supply Chain Security

5 articles
Cybersecurity 22 Sep 2026 7 min read

Subresource Integrity Pins Browser-Loaded Assets to Approved Bytes

Subresource Integrity Pins Browser-Loaded Assets to Approved Bytes A web page can load executable code from infrastructure outside the application’s deployment boundary. A <script> URL may point to a CDN, a package distribution endpoint, or another origin operated under a separate release process. TLS protects the connection to that endpoint, but a valid HTTPS response can still contain bytes different from the version the page author intended to run. Subresource Integrity, commonly shortened to SRI, adds a content check at the browser. The document carries cryptographic digest metadata for a resource. After fetching the resource, the browser computes the applicable digest and compares it with the metadata before accepting the resource for the protected use.

Cybersecurity 21 Sep 2026 5 min read

Subresource Integrity Pins External Assets to Expected Content

Subresource Integrity Pins External Assets to Expected Content A page that loads JavaScript or CSS from another host gives that host a direct path into the page’s execution or presentation context. HTTPS protects the transfer against network tampering, but it does not tell the browser whether the server returned the exact asset the application intended to use. Subresource Integrity (SRI) adds a content check. The document carries cryptographic metadata for a resource. After fetching the bytes, the browser computes the relevant digest and compares it with the metadata before accepting the resource.

Cybersecurity 20 Sep 2026 5 min read

Subresource Integrity Pins Browser Execution to Expected Bytes

Subresource Integrity Pins Browser Execution to Expected Bytes A web page can fetch JavaScript and stylesheets from infrastructure outside the application’s deployment boundary. A CDN improves distribution, but the browser normally treats the response from the referenced URL as the resource the page requested. If that response changes unexpectedly, transport security alone does not tell the browser that the bytes differ from the version selected by the application operator. Subresource Integrity (SRI) adds a content check to that load. The page carries cryptographic metadata for an expected representation. A supporting browser hashes the fetched resource and accepts it only when the result satisfies the declared integrity metadata.

Cybersecurity 15 Sep 2026 7 min read

Subresource Integrity Pins External Assets to Expected Bytes

Subresource Integrity Pins External Assets to Expected Bytes A web page can keep all of its application code under careful review and still execute JavaScript delivered from infrastructure outside its control. Analytics libraries, UI frameworks, payment components, and other dependencies are often fetched from a content delivery network. If that remote response changes, the browser normally has no basis for deciding whether the new bytes are an approved release or an unexpected substitution.

Cybersecurity 14 Sep 2026 6 min read

Subresource Integrity Pins Browser Dependencies to Expected Bytes

Subresource Integrity Pins Browser Dependencies to Expected Bytes A production page can contain no application-side injection flaw and still execute hostile JavaScript if a trusted external asset changes underneath it. The script URL may be correct, TLS may be valid, and the browser may have reached the intended host. None of those facts establish that the returned file is the exact artifact the site operator approved. Subresource Integrity, commonly shortened to SRI, adds that missing assertion for selected browser-loaded scripts and stylesheets. An integrity attribute carries one or more cryptographic digest values. After fetching the resource, the browser computes the digest of the representation used for the integrity check and refuses to apply or execute it when no supported digest matches.