Skip to content

Add SRI (Subresource Integrity) hash to CDN script tags #5165

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 12 commits into from
Jun 11, 2025
Merged
Prev Previous commit
Fix formatting
  • Loading branch information
ddworken committed Jun 10, 2025
commit 7a99cd787663e58d9b433e4b4f5ed56c7ba88edd
4 changes: 3 additions & 1 deletion tests/test_core/test_offline/test_offline.py
Original file line number Diff line number Diff line change
Expand Up @@ -39,7 +39,9 @@
<script type="text/javascript">\
window.PlotlyConfig = {MathJaxConfig: 'local'};</script>"""

cdn_script = '<script charset="utf-8" src="{cdn_url}" integrity="{js_hash}" crossorigin="anonymous"></script>'.format(cdn_url=plotly_cdn_url(), js_hash=_generate_sri_hash(get_plotlyjs()))
cdn_script = '<script charset="utf-8" src="{cdn_url}" integrity="{js_hash}" crossorigin="anonymous"></script>'.format(
cdn_url=plotly_cdn_url(), js_hash=_generate_sri_hash(get_plotlyjs())
)

directory_script = '<script charset="utf-8" src="plotly.min.js"></script>'

Expand Down