Advertisement
Home Open Editor ❯

HTML <script> integrity Attribute

Example

<script src="https://cdn.jsdelivr.net/npm/bootstrap@5.1.0/dist/js/bootstrap.bundle.min.js" integrity="sha384-U1DAWAznBHeqEIlVSCgzq+c9gqGAJn5c/t99JyeKa9xxaYpSvHU5awsuZVVFIhvj" crossorigin="anonymous"></script>

Meaning

The integrity attribute contains inline metadata that a user agent can use to verify that a fetched resource has been delivered free of unexpected manipulation.

Subresource Integrity (SRI) is a security feature that enables browsers to verify that resources they fetch (for example, from a CDN) are delivered without unexpected manipulation. It works by allowing you to provide a cryptographic hash that a fetched resource must match.

Note: Note: For subresource-integrity verification of a resource served from an origin other than the document in which it’s embedded, browsers additionally check the resource using Cross-Origin Resource Sharing (CORS), to ensure the origin serving the resource allows it to be shared with the requesting origin.


Standard Syntax

<script integrity="filehash"></script>


Advertisement

Attribute Values

Value Description
filehash The file hashing value of the external script file
Home Open Editor ❯
Advertisement