-
Notifications
You must be signed in to change notification settings - Fork 70
Open
Labels
Description
Hello,
I've recently started to use Rive and observed wasm fallback behavior:
Line 258 in 2d92a14
| const backupJsdelivrUrl = `https://cdn.jsdelivr.net/npm/${packageData.name}@${packageData.version}/rive_fallback.wasm`; |
While I understand why this might be useful and bulletproof, it is also a security risk because your application will download a resource from a third-party CDN without any integrity or control over it. As far as I can see, there is no option to disable or configure this fallback.
Perhaps you could consider adding such an option? Either disable it or provide a fallback URL the same way as it is done for the "first party" wasm URL.