Hacker News
new
past
comments
ask
show
jobs
points
by
runtime_terror
2 hours ago
|
comments
by
bdcravens
18 minutes ago
|
next
[-]
Can be mitigated, as the sibling comment points out, but even in the situation you described, the blast radius is reduced, especially for frontend libs.
reply
by
phpdave11
2 hours ago
|
prev
|
[-]
As long as you embed it with an SRI integrity hash, you're safe, even if the remote server is compromised.
reply