Subresource Integrity

Pin a released version and verify downloaded files against trusted expected bytes.

Published v2.0.0 reference

These SHA-384 hashes were computed from the GitHub v2.0.0 release ZIP on 2026-10-10. All four files were compared byte-for-byte with the versioned CDN files and matched. These hashes describe that published release, not unreleased dev builds.

FileIntegrity
focus-ui.csssha384-D7X0gF1+ziNGfdkLmE5yx3ttB7EjaxF+fc6h06iPmNkAu6Pzee/GcgdZzgJRNiWV
focus-ui.jssha384-za2gdEv7hvS5K/vvOFr3K/KkxJijiJqdraUx8/wR1fGKjTYU35HUTTChtx+KTQHo
focus-ui.min.jssha384-XAPpQn2K20UWENWT92uR4+Kk8BN7jgVTWvkfWiOtCoO0MmvlOgj8LBueELLhB/sc
focus-ui.esm.jssha384-9N0/rH8gjpnl2MsrAyyYRV4ZmRqK2iH6BASLiUay6lqbpMiq3NP4yZQw041TtSsV

HTML usage

Use crossorigin="anonymous" for cross-origin integrity checks. The CDN must send an appropriate CORS response; the checked v2.0.0 files returned Access-Control-Allow-Origin: *.

HTML
<link rel="stylesheet"
  href="https://cdn.focus-ui.de/v2.0.0/focus-ui.css"
  integrity="sha384-D7X0gF1+ziNGfdkLmE5yx3ttB7EjaxF+fc6h06iPmNkAu6Pzee/GcgdZzgJRNiWV"
  crossorigin="anonymous">
<script defer src="https://cdn.focus-ui.de/v2.0.0/focus-ui.min.js"
  integrity="sha384-XAPpQn2K20UWENWT92uR4+Kk8BN7jgVTWvkfWiOtCoO0MmvlOgj8LBueELLhB/sc"
  crossorigin="anonymous"></script>

Choose the expected hash independently

SRI detects a mismatch against an expected hash; it does not prove the original release is safe. Obtain and review release files through a trusted channel before pinning their hashes. Metadata served by the same CDN is convenient for lookup but is not an independent trust anchor if that CDN is compromised.

The current v2.0.0 GitHub release contains a ZIP only; it has no SRI.txt asset and is not marked immutable. This recovery adds SRI.txt generation to future releases and integrity fields to future CDN metadata. Do not assume every historical release is signed or immutable.

Compute hashes for another release

Download and extract the approved release ZIP, then hash the exact asset bytes. Do not reuse these v2.0.0 values for another version or for latest/.

Bash
openssl dgst -sha384 -binary focus-ui.min.js | openssl base64 -A
# Prefix the resulting base64 value with sha384- in the integrity attribute.

Diagnose integrity failures

Check the version URL, expected bytes, CORS headers and crossorigin attribute. A changed file requires a new reviewed hash. When an integrity check fails, browsers block the resource; do not remove the check merely to hide the error.

Reference: MDN Subresource Integrity.