Hey folks! Think you could upstream the integrity
attribute to HTML? I'm thinking about integrating with it for CSP (along the lines of "Hash source expressions will whitelist external scripts that declare a matching integrity
attribute", which seems like a reasonable extension). To do that, y'all need to start populating integrity information from HTML, which currently doesn't have much understanding of this mechanism.
whatwg/fetch#285 demonstrates about half of what you'd need to do. The other half would be defining the attributes, which I think you can do by copy/pasting from nonce
in various places.
RetroSearch is an open source project built by @garambo | Open a GitHub Issue
Search and Browse the WWW like it's 1997 | Search results from DuckDuckGo
HTML:
3.2
| Encoding:
UTF-8
| Version:
0.7.4