1. 程式人生 > >Ask HN: How do you make sure js from a CDN or a CMS hasn't changed?

Ask HN: How do you make sure js from a CDN or a CMS hasn't changed?

SRI won't protect you from:

* Someone injecting malicious JS code into your checkout page

* Non-static JS includes like Google Analytics

But it works well for static assets like jQuery or other static JS resources.