-
Notifications
You must be signed in to change notification settings - Fork 35
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Revert require-sri-for
#82
Conversation
hmm this makes me sad too. We use it at Dropbox a lot too. Can you say more whats the reason its causing so much pain? |
welp .. just saw your other messages on how this ship's already sailed. |
Can you post some references why it was done to better understand reasons of this removal for outsiders? |
Thank you for asking. I should have made the pointer earlier. Please see this thread on the webappsec working group mailing list for more information. The mailing list is public and open for further commentary, so let's move all discussion there. |
It is being removed from Firefox and planned to be removed from Chromium. It seems the main reason is that it doesn't cover all scripts/styles and therefore provide a false sense of security and may break in the future. See <w3c/webappsec-subresource-integrity#82>.
In w3c/webappsec-subresource-integrity#82, the require-sri-for feature was dropped from the spec. So this change updates its BCD status to "standard_track": false, "deprecated": true
w3c/webappsec-subresource-integrity#82 removed `require-sri-for` from the SRI spec.
In w3c/webappsec-subresource-integrity#82, the require-sri-for feature was dropped from the spec. So this change updates its BCD status to "standard_track": false, "deprecated": true
w3c/webappsec-subresource-integrity#82 removed `require-sri-for` from the SRI spec.
w3c/webappsec-subresource-integrity#82 removed `require-sri-for` from the SRI spec.
w3c/webappsec-subresource-integrity#82 removed `require-sri-for` from the SRI spec.
I really liked the feature. 😢
However, we ended up unshipping in Gecko and IIRC @mikewest considered removing from Blink, so I'm making an attempt at removing
require-sri-for
.Preview | Diff