plotly / plotly/dash

Generate integrity hash for the components bundles and use them when serving.

Open
#422 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

feature infrastructure P3
Dominant language
Python
Stars
24.4k
Forks
2.3k
Avg merge
2d 7h
Merged PRs (30d)
13

Description

Currently we don't include the integrity hash in the bundles we serve.

Dash:

  • include the integrity hash in scripts/css tags.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by locating where the components bundles are served and where the scripts and CSS tags are generated. Trace how the bundle assets are selected, then verify that served tags include matching integrity hashes for both scripts and styles.

Written by the indexing model from the issue text.

Assessment

Tech stack
python, react
Domain
frontend, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.