NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #4094 most downloaded on npm
Webpack plugin for enabling Subresource Integrity
Last release 4 years ago
no release in 18 months
Release timing varies
gaps range from 2 weeks to 1.1 years
Nearly every release is documented
notes for 32 of 35 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
50 releases · first in 2015
Performance optimizations for big projects
Allow deferred loading of hashes. Specifying the new option hashLoading: "lazy" will cause integrity hashes for any given asset to be defined in its d
hashLoading: "lazy" will cause integrity hashes for any given asset to be defined in its direct parents in the chunk graph. This can lead to duplication of hashes across assets, but can significantly reduce the size of entry chunk(s) when there are a large number of async chunks. (#171)One column per quarter.
No changes compared to v5.0.0-rc.1.
No changes compared to v5.0.0-rc.1.
Changes compared to v1.5.2:
(See migrating from v1 to v5.)
SubresourceIntegrityPlugin.enabled now defaults to "auto", which enables the plugin in all Webpack modes except for development. Previously, the plugin was disabled by default in all modes.hashFuncNames now has a default: ["sha384"].Warn when using dangerous filename hashes
Fix handling of chunks with multiple files
Fix real content hash generation
Adds compatibility with Next.js 10.0.6. Please note that installing this plugin in Next.js is not enough to gain integrity since top-level assets will
Do not import webpack (#150)
Adds compatibility with Next.js 10.0.6. Please note that installing this plugin in Next.js is not enough to gain integrity since top-level assets will remain unprotected.
Fix error when a processed tag has no attributes
Drop compatibility with Webpack < 5.12.0.
SubresourceIntegrityPlugin.enabled now defaults to "auto", which enables the plugin in all Webpack modes except for development. Previously, the plugin was disabled by default in all modes.hashFuncNames now has a default: ["sha384"].Fix dynamic loading of named chunks in Webpack 5
Fix a security issue where dynamically loaded chunks were not protected from tampering. This issue was introduced in v1.5.0.
- Compatibility with Webpack 5
Ignore tags with null attributes
Add integrity to link preload tags
Fix warning when used with webpack-fix-style-only-entries
Fix source maps in projects with code splitting
require-sri<link preload>Fix bug where in some cases runtime bundle contents changed needlessly and without contenthash changing
Fix bug when used alongside html-webpack-externals-plugin
peerDependenciesMeta) (#90)Support for assets added in html-webpack-plugin-before-html-generation hook, for example by add-asset-html-webpack-plugin
html-webpack-plugin-before-html-generation hook, for example by add-asset-html-webpack-plugin (#51)Replace webpack-core dependency by webpack-sources
Document webpack-asset-manifest integration
Avoid duplicate error message on Webpack 4.20
Fix a bug occurring in a certain constellation (Webpack 4 with splitChunks optimization in production mode plus mini-css-extract-plugin) by simplifyin
Fix incompatibility with Webpack 4.13+ where the crossOrigin attribute wasn't always set.
crossOrigin attribute wasn't always set.contenthash placeholder. (#78)Fix bug with multiple files per chunk
Improve warning for incorrect crossOriginLoading setting
crossOriginLoading setting (#64)- Add missing distribution files
Turn Webpack-based test cases into examples
Fix bug with multiple commons chunks
More robust path matching, fixes errors with certain ExtractTextPlugin output path formats
Fix error with chunk names that are not valid JS identifiers (#53) @tyscorp
Fix peerDependencies for Webpack 3.x
Ensure compatibility with Webpack 3 and Node 8
Remove deprecated code BREAKING
crossorigin option is no longer supported, use webpack option output.crossOriginLoading instead (#20)eslint-config-airbnb-base/legacyRemove compatibility with Webpack 2 release candidates
Recommend Cache-Control: no-transform when using plain HTTP
Cache-Control: no-transform when using plain HTTPNothing published for this version
Deprecate crossorigin option and warn if webpack output.crossOriginLoading option isn't set
Deprecate crossorigin option and warn if webpack output.crossOriginLoading option isn't set (#20)
This release deprecates passing an array of hash function names directly to the plugin constructor. You should update your code accordingly. See #18 f…
enabled and crossorigin options (#18)This release deprecates passing an array of hash function names directly to the plugin constructor. You should update your code accordingly. See #18 for details.
Fix deprecation warning with newer versions of html-webpack-plugin
Bugfix for handling assets in subdirectories with html-webpack-plugin.
Bugfix for handling assets in subdirectories with html-webpack-plugin.
Compatibility with webpack 2.1.0-beta
Compatibility with webpack 2.1.0-beta (#8)
Handle circular chunk dependencies gracefully.
Handle circular chunk dependencies gracefully.
Emit warning instead of error when a foreign asset is added by html-webpack-plugin.
Fix handling of filename hashes added by html-webpack-plugin.
Relax version requirements for development dependencies.
Nothing published for this version
Add integration with html-webpack-plugin. (Thanks @SPSpwetter!)
Add integration with html-webpack-plugin. (Thanks @SPSpwetter!)
Upgrade development dependencies.
Minor tweaks to README.
Don't rely on presence of Object.values.
Don't rely on presence of Object.values.
Don't rely on presence of Array.forEach.
Don't rely on presence of Array.forEach.
Compute integrity for non-JS assets.
Compute integrity for non-JS assets.
Internal improvements for better forward compatibility with webpack.
Internal improvements for better forward compatibility with webpack.
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →