rspec/rules/S5725/html/rule.adoc

45 lines
805 B
Plaintext
Raw Permalink Normal View History

2021-02-10 17:04:49 +01:00
include::../description.adoc[]
include::../ask-yourself.adoc[]
include::../recommended.adoc[]
== Sensitive Code Example
The following code sample uses neither integrity checks nor version pinning:
[source,html]
2021-02-10 17:04:49 +01:00
----
<script
src="https://cdn.example.com/latest/script.js"
></script> <!-- Sensitive -->
2021-02-10 17:04:49 +01:00
----
== Compliant Solution
2022-02-04 17:28:24 +01:00
[source,html]
2021-02-10 17:04:49 +01:00
----
<script
src="https://cdn.example.com/v5.3.6/script.js"
integrity="sha384-oqVuAfXRKap7fdgcCY5uykM6+R9GqQ8K/uxy9rx7HNQlGYl1kPzQho1wx4JwY8wC"
></script>
2021-02-10 17:04:49 +01:00
----
include::../see.adoc[]
ifdef::env-github,rspecator-view[]
'''
== Implementation Specification
(visible only on this page)
include::../message.adoc[]
'''
== Comments And Links
(visible only on this page)
include::../comments-and-links.adoc[]
endif::env-github,rspecator-view[]