Skip to content

Commit 74f282e

Browse files
committed
chore: add SRI and security attributes to CDN assets
- remove deprecated X-UA-Compatible meta tag - add integrity, crossorigin, and referrerpolicy to GitHub ribbon CSS - add integrity, crossorigin, and referrerpolicy to jQuery CDN script - modernize external resource loading for improved security and CodeQL compliance
1 parent 03d0714 commit 74f282e

1 file changed

Lines changed: 12 additions & 3 deletions

File tree

_includes/head.html

Lines changed: 12 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,5 @@
11
<head>
22
<meta charset="utf-8" />
3-
<meta http-equiv="X-UA-Compatible" content="IE=edge" />
43
<meta name="viewport" content="width=device-width, initial-scale=1" />
54
<meta name="author" content="Jay Prall" />
65
<meta name="robots" content="follow" />
@@ -11,8 +10,18 @@
1110
<link rel="stylesheet" href="{{ "/css/main.css" | prepend: site.baseurl }}">
1211
<link rel="canonical" href="{{ page.url | replace:'index.html','' | prepend: site.baseurl | prepend: site.url }}">
1312
<link rel="alternate" type="application/rss+xml" title="{{ site.title }}" href="{{ "/feed.xml" | prepend: site.baseurl | prepend: site.url }}" />
14-
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/github-fork-ribbon-css/0.2.3/gh-fork-ribbon.min.css" />
1513

16-
<script src="https://cdnjs.cloudflare.com/ajax/libs/jquery/3.7.0/jquery.min.js" type="text/javascript"></script>
14+
<link
15+
rel="stylesheet"
16+
href="https://cdnjs.cloudflare.com/ajax/libs/github-fork-ribbon-css/0.2.3/gh-fork-ribbon.min.css"
17+
integrity="sha512-1JtYwcmBHQYaWV7k/akdUSHhDuD1ynjUTduVdJN9WewtG/XAIN5e8wZsM+dAf5BgU984wgKLF6ig84yYI6FzPA=="
18+
crossorigin="anonymous"
19+
referrerpolicy="no-referrer"
20+
/>
21+
<script
22+
src="https://cdnjs.cloudflare.com/ajax/libs/jquery/3.7.0/jquery.min.js"
23+
integrity="sha512-3gJwYp8pG+YkYgPp0tY6Yv3tQYVt8i1Cdm42Hcps225y7sY9qsK0kGugHgdGXN53BJ38qJjPR9U1FVLtZLkYBg=="
24+
crossorigin="anonymous"
25+
referrerpolicy="no-referrer"></script>
1726
<script async src="https://pagead2.googlesyndication.com/pagead/js/adsbygoogle.js"></script>
1827
</head>

0 commit comments

Comments
 (0)