Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Provide Subressource Integrity #7

Open
nbraud opened this issue Nov 15, 2019 · 2 comments
Open

Provide Subressource Integrity #7

nbraud opened this issue Nov 15, 2019 · 2 comments

Comments

@nbraud
Copy link
Contributor

nbraud commented Nov 15, 2019

Subressource Integrity is a standard feature of HTML, that lets us specify a hash when loading a ressource (say, a script, a CSS stylesheet, ...).

Currently, we are loading ressources from cdnjs.cloudflare.com without specifying their hash, so Cloudflare (or anyone successfully impersonating them) could inject evil content there.

This looks like it's an issue in mkdocs (or at least its default theme)

@nbraud
Copy link
Contributor Author

nbraud commented Nov 15, 2019

Confirmed and reported upstream: mkdocs/mkdocs#1905

@nbraud
Copy link
Contributor Author

nbraud commented Nov 15, 2019

Wrote a PR: mkdocs/mkdocs#1906

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant