feat: add sri integrity hash for redoc#2911
Merged
Merged
Conversation
🦋 Changeset detectedLatest commit: 1cebfd4 The changes in this PR will be included in the next version bump. This PR includes changesets to release 3 packages
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
Contributor
Coverage Report
File Coverage
|
||||||||||||||||||||||||||||||||||||||||||||||||||
Contributor
Performance Benchmark (Lower is Faster)
|
2ffd5fa to
d796ca2
Compare
d796ca2 to
a64ba58
Compare
JLekawa
reviewed
Jun 26, 2026
Co-authored-by: Jacek Łękawa <164185257+JLekawa@users.noreply.github.com>
vadyvas
approved these changes
Jun 26, 2026
JLekawa
approved these changes
Jun 26, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What/Why/How?
Added the integrity attribute for Redoc standalone:
Reference
Closes #2875
Check yourself
Security
Note
Medium Risk
Generated docs depend on a manually maintained SRI hash matching the CDN bundle; a Redoc bump without updating the hash will break pages or fail CI, but the change hardens against CDN tampering.
Overview
build-docsnow emits the CDNredoc.standalone.js<script>withintegrity(sha384) andcrossorigin="anonymous", using a newredocStandaloneSriconstant inpackage.tsthat must stay in sync with the pinned Redoc version.The build-docs option field is renamed from
redocCurrentVersiontoredocVersion. CONTRIBUTING documents how to recompute the hash when bumping Redoc.Coverage includes an e2e test that fetches the live CDN bundle and asserts the embedded hash matches, plus updated HTML snapshots and smoke pre-built output.
Reviewed by Cursor Bugbot for commit 1cebfd4. Bugbot is set up for automated code reviews on this repo. Configure here.