logoalt Hacker News

runtime_terrortoday at 3:01 PM3 repliesview on HN

Except now you're making http calls to remote servers that could be compromised.


Replies

grugdev42today at 7:38 PM

This is a solved problem.

Use HTTPS and use the integrity attribute.

https://developer.mozilla.org/en-US/docs/Web/HTML/Reference/...

Also, what's more likely? Someone hacking jsDelivr/cdnjs OR some random NPM packages getting hacked?

bdcravenstoday at 5:33 PM

Can be mitigated, as the sibling comment points out, but even in the situation you described, the blast radius is reduced, especially for frontend libs.

phpdave11today at 3:30 PM

As long as you embed it with an SRI integrity hash, you're safe, even if the remote server is compromised.