T08 · Insecure Dependencies
- Location
references/adapters.md:78- Finding
Unpinned Runtime CSS Dependency from a Third-Party CDN
- Content
View full analysis
- Remediation
View remediation
` with a verified Subresource Integrity hash and `crossorigin="anonymous"`. - CSS `@import` does not provide an equivalent SRI attribute, so it should not be recommended for security-sensitive remote dependencies. 4. **Restrict browser network access** - Configure a Content Security Policy with a narrow `style-src`. - Restrict `img-src`, `font-src`, and related directives to prevent imported CSS from freely loading attacker-controlled secondary resources. 5. **Use local first-party tokens by default** - Make `references/token-core.css` the default and sufficient source of design tokens. - Remove the remote import recommendation unless the user explicitly requests Open Props and accepts the external dependency. 6. **Add dependency governance** - Track the vendored or pinned release in dependency review tooling. - Review upstream changes before upgrades. - Test visual integrity and application behavior after each approved update. ]]>
