<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>SRI on Nalar</title>
    <link>https://nalar.dev/tags/sri/</link>
    <description>Recent content in SRI on Nalar</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Tue, 15 Sep 2026 00:00:00 +0700</lastBuildDate>
    <atom:link href="https://nalar.dev/tags/sri/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Subresource Integrity Pins External Assets to Expected Bytes</title>
      <link>https://nalar.dev/subresource-integrity-pins-external-assets-to-expected-bytes/</link>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0700</pubDate>
      <guid>https://nalar.dev/subresource-integrity-pins-external-assets-to-expected-bytes/</guid>
      <description>&lt;h1 id=&#34;subresource-integrity-pins-external-assets-to-expected-bytes&#34;&gt;Subresource Integrity Pins External Assets to Expected Bytes&lt;/h1&gt;&#xA;&lt;p&gt;A web page can keep all of its application code under careful review and still execute JavaScript delivered from infrastructure outside its control. Analytics libraries, UI frameworks, payment components, and other dependencies are often fetched from a content delivery network. If that remote response changes, the browser normally has no basis for deciding whether the new bytes are an approved release or an unexpected substitution.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
