Definition · Security Headers

What is Subresource Integrity?

Loading a script from a CDN or a third-party provider is an act of trust: whatever that host serves will execute with the full privileges of your origin. Subresource Integrity, specified by the W3C, reduces that trust to a specific known file. The tag carries a hash of the expected contents, the browser computes the hash of what it received, and if they differ the resource is discarded and never executed.

<script src="https://cdn.example.com/lib-3.2.1.min.js"
        integrity="sha384-oqVuAfXRKap7fdgcCY5uykM6+R9GqQ8K/uxy9rx7HNQlGYl1kPzQho1wx4JwY8wC"
        crossorigin="anonymous"></script>

The integrity attribute holds a base64 digest prefixed with the algorithm — sha256, sha384 or sha512. Several space-separated hashes may be listed, and the resource is accepted if any one matches, which allows a rollover between versions. The crossorigin attribute is required for cross-origin resources, because the browser needs a CORS-enabled response to read the body for hashing.

What it protects against

  • A compromised CDN or third-party provider serving modified code
  • A compromised or hijacked hostname that a page depends on, including one lost to subdomain takeover
  • Tampering in transit where TLS is absent or broken, overlapping with the mixed content protections
  • Accidental substitution of the wrong build

Limits

SRI applies only to <script> and <link> elements, so images, iframes and dynamically fetched resources are outside its scope. It requires the file to be immutable: pinning a hash to a URL that the provider updates in place will break the page on the next release, which is why SRI and “always latest” CDN URLs are incompatible. It also protects only the file you hashed — a script that loads further scripts at runtime is unconstrained, which is a common reason tag managers and analytics loaders cannot be usefully pinned.

Because a mismatch blocks the resource, a wrong or stale hash is an availability risk. Generate hashes as part of the build rather than by hand, and pair SRI with a CSP that restricts which hosts may serve script at all: CSP controls where code may come from, SRI controls what that code may be.

See CSP, cross-site scripting, CORS misconfiguration, defence in depth and security headers.

See what your business is exposing

SurfaceLoop checks every internet-facing asset you own across seven risk categories, daily.