ar.al🌻 · @aral
21222 followers · 19353 posts · Server mastodon.ar.al

Finally found the time to open a discussion on the Snowpack forums about the lack of subresource integrity (SRI) in Skypack: github.com/snowpackjs/snowpack

(Background: my post from the end of last year titled Skypack: backdoor as a Service? ar.al/2020/12/30/skypack-backd)

#privacy #security #sri #subresourceintegrity #Snowpack #skypack

Last updated 4 years ago

ar.al🌻 · @aral
21222 followers · 19353 posts · Server mastodon.ar.al

If you specify subresource integrity in a script tag and then import that script also from a separate tag later on, and the source fails the integrity check, on

1. Firefox (Gecko): script doesn’t execute
2. Ungoogled Chromium (Chromium): script doesn’t execute
3. Epiphany (WebKit): script tag is blocked but script executes via the import

Not sure if Safari does the same but that’s not good.

#security #subresourceintegrity

Last updated 4 years ago

ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online