All fixes

Add integrity hashes to CDN scripts

content-sri

A script loaded from a CDN runs with your privileges. An integrity hash makes the browser refuse it if the file ever changes underneath you.

Next.js

  1. 1 Add integrity attributes to external script/link tags
  2. 2 Generate hashes with: shasum -b -a 384 file.js | awk '{print $1}' | xxd -r -p | base64
html
<script
  src="https://cdn.example.com/lib.js"
  integrity="sha384-oqVuAfXRKap7fdgcCY5uykM6+R9GqQ8K/uxy9rx7HNQlGYl1kPzQho1wx4JwY8wC"
  crossorigin="anonymous"
/>

Does your app still have this?

Scan your domain