Closed (won't fix)
Project:
Siteimprove.ai
Version:
8.x-1.x-dev
Component:
Code
Priority:
Normal
Category:
Task
Assigned:
Reporter:
Created:
5 May 2020 at 12:17 UTC
Updated:
28 Jan 2022 at 13:39 UTC
Jump to comment: Most recent, Most recent file
Comments
Comment #2
wil2091 commentedAdded the integrity attribute to the external js https://cdn.siteimprove.net/cms/overlay.js
Please verify the patch.
Here are the screenshots of the view source page & network
Comment #3
wil2091 commentedComment #4
beltofteHi @wil2091 ,
Thanks for your patch. I will discuss it with Siteimprove and decided if we should add it or not.
Best regards,
Jens
Comment #5
beltofteComment #7
beltofteComment #9
beltofteWe will revert this change and remove the SRI hash from the library file. Siteimprove is currently not supporting versioning of their overlay.js file, and this means that every time Siteimprove release an updated version of overlay.js, will browsers immediately block the overlay.js file and we will have to release a new version of the module with an updated hash. We are discussing with Siteimprove to support versioning of their overlay.js file and if/when they support it will we add a SRI hash again.
Comment #11
beltofteFixed in 8.x-1.7.
Comment #12
bartvig commented