Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
thenewnewguy
on Oct 26, 2019
|
parent
|
context
|
favorite
| on:
Gitlab ‘rethinking’ third-party telemetry
Doesn't prevent a malicious/compromised third party from serving code other than what's in the source. I think an acceptable mitigation might be subresource integrity though, so you can lock it to a known-good version of a script?
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: