fix: pin Swagger UI CDN assets with SRI - #4082
Merged
Merged
Conversation
Replace unversioned unpkg imports with pinned swagger-ui-dist@5.11.0 and load stylesheets via link tags so integrity can be enforced. Based on the intent of #3807 (which used a placeholder integrity value).
Contributor
Contributor
💻 Website PreviewThe latest changes are available as preview in: https://pr-4082.fets-3ku.pages.dev |
Contributor
✅ Benchmark Results |
There was a problem hiding this comment.
Pull request overview
This PR hardens the Swagger UI HTML template by switching CDN-loaded Swagger UI assets to version-pinned URLs and adding Subresource Integrity (SRI) + crossorigin attributes so browsers can verify the fetched bytes.
Changes:
- Replace CSS
@importwith<link>tags so SRI can be enforced for stylesheets. - Pin
swagger-ui-distCDN URLs to@5.11.0and addsha384integrity hashes for CSS and JS. - Add a changeset documenting the security hardening.
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated 2 comments.
| File | Description |
|---|---|
| packages/fets/src/swagger-ui.html | Pins Swagger UI assets and adds SRI/crossorigin; moves theme CSS from @import to <link>. |
| .changeset/swagger-ui-sri.md | Documents the SRI/pinning change as a patch release note. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
2 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
swagger-ui-distto5.11.0and load CSS/JS with real Subresource Integrity hashes@importto<link>sointegrityis enforceableSupersedes #3807 (that PR pinned the version but used a placeholder
integrityvalue that would break Swagger UI in browsers).Test plan
sha384digests match the HTML attributes