Generate integrity hash for the components bundles and use them when serving.
Open
Nobody has claimed this yet.
feature
infrastructure
P3
- Dominant language
- Python
- Stars
- 24.4k
- Forks
- 2.3k
- Avg merge
- 2d 7h
- Merged PRs (30d)
- 13
Description
Currently we don't include the integrity hash in the bundles we serve.
Dash:
- include the integrity hash in scripts/css tags.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by locating where the components bundles are served and where the scripts and CSS tags are generated. Trace how the bundle assets are selected, then verify that served tags include matching integrity hashes for both scripts and styles.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- python, react
- Domain
- frontend, security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 25/100