|
|
|
|
|
by no_wizard
480 days ago
|
|
Vendor your dependencies. It’s better for you as a maintainer anyway, since caching only works[0] with first party domains with any reliability. And once you vendor your dependencies you can calculate the hash yourself [0]: there are caveats to this |
|
I think https and integrity hashes address two very orthogonal attack vectors.