SRI: The `require-sri-for` CSP directive.

The `require-sri-for` directive gives developers the ability to assert to the browser that every resource of a given type ought to be integrity checked. If a resource of that type is loaded without integrity metadata, it will be rejected without triggering a network request.


Editor's draft

Status in Chromium


Behind a flag (tracking bug) in:

  • Chrome for desktop release 54
  • Chrome for Android release 54
  • Android WebView release 54

Consensus & Standardization

After a feature ships in Chrome, the values listed here are not guaranteed to be up to date.

  • In development
  • No public signals
  • No public signals
  • Positive


Last updated on 2017-06-14