A security feature that lets browsers verify the integrity of resources fetched from CDNs via a cryptographic hash.
If your site loads jQuery from a CDN, an attacker who compromises the CDN can replace it with malicious code. SRI mitigates that: <script integrity="sha384-..."> tells the browser to refuse a mismatched file.
See our web application penetration testing, API security testing, network penetration testing, and cloud security audit services for how we test for and defend against this class of issue.
30-minute call with an OSCP-certified engineer. Tailored proposal in 24 hours.