# vite-plugin-manifest-sri

> Subresource Integrity hashes for the Vite.js manifest.

Latest version **0.2.0** (published 2023-11-16) · MIT license · 0 weekly downloads

## Install

```sh
npm install vite-plugin-manifest-sri
pnpm add vite-plugin-manifest-sri
yarn add vite-plugin-manifest-sri
bun add vite-plugin-manifest-sri
```

## Health

**Score 30/100 (F)** — status: abandoned.

Positive: has types; esm support; no vulnerabilities; high quality score.

Warnings: low downloads; pre 1.0.

Negative: abandoned; low maintenance score.

## Facts

| | |
|---|---|
| Version | 0.2.0 |
| Published | 2023-11-16 |
| First published | 2022-01-18 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | bundled |
| Module format | ESM + CommonJS |
| Dependencies | 0 |
| Unpacked size | 14.2 KB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| Author | Máximo Mussini |
| Maintainers | elmassimo |
| Keywords | sri, security, subresource integrity, build, vite, vite-plugin, vitejs, plugin |

## Links

- npm: https://www.npmjs.com/package/vite-plugin-manifest-sri
- Repository: https://github.com/ElMassimo/vite-plugin-manifest-sri
- Issues: https://github.com/ElMassimo/vite-plugin-manifest-sri/issues
- npm.io page: https://npm.io/package/vite-plugin-manifest-sri

## Alternatives

- [raw-loader](https://npm.io/package/raw-loader.md) — 4.3M weekly downloads
- [plop](https://npm.io/package/plop.md) — 1.4M weekly downloads
- [webpack-deadcode-plugin](https://npm.io/package/webpack-deadcode-plugin.md) — 80.3K weekly downloads
- [@storybook/preact-vite](https://npm.io/package/@storybook/preact-vite.md) — 54.2K weekly downloads
- [vite-plugin-transform](https://npm.io/package/vite-plugin-transform.md) — 2.4K weekly downloads

## Recent versions

- 0.2.0 (latest) — 2023-11-16
- 0.1.0 — 2022-01-18

## README

<h2 align='center'>
  <samp>vite-plugin-manifest-sri</samp>
</h2>

<p align='center'>Subresource Integrity for Vite.js Manifests</p>

<p align='center'>
  <a href='https://www.npmjs.com/package/vite-plugin-manifest-sri'>
    <img src='https://img.shields.io/npm/v/vite-plugin-manifest-sri?color=222&style=flat-square'>
  </a>
  <a href='https://github.com/ElMassimo/vite-plugin-manifest-sri/blob/main/LICENSE.txt'>
    <img src='https://img.shields.io/badge/license-MIT-blue.svg'>
  </a>
</p>

<br>

[Vite]: https://vitejs.dev/
[Vite Ruby]: https://github.com/ElMassimo/vite_ruby
[SRI]: https://developer.mozilla.org/en-US/docs/Web/Security/Subresource_Integrity
[manifest]: https://vitejs.dev/guide/backend-integration.html#backend-integration

[rollup-plugin-sri]: https://github.com/JonasKruckenberg/rollup-plugin-sri
[vite-plugin-sri]: https://github.com/small-tech/vite-plugin-sri
[manifest]: https://vitejs.dev/guide/backend-integration.html
[rendering]: https://vite-ruby.netlify.app/overview.html#in-production

## Why? 🤔

[Vite] does [not provide support](https://github.com/vitejs/vite/issues/2377) for [subresource integrity][sri].

Both <kbd>[vite-plugin-sri]</kbd> and <kbd>[rollup-plugin-sri]</kbd> are good
options to automatically add an [`integrity`][sri] hash to script and link tags. However, these rely on transforming an HTML file, which is typically not the case when using a backend integration such as [Vite Ruby].

This plugin extends [`manifest.json`][manifest] to include an [`integrity`][sri] field which can be used when [rendering] tags.

## Installation 💿

Install the package as a development dependency:

```bash
npm i -D vite-plugin-manifest-sri # pnpm i -D vite-plugin-manifest-sri
```

## Usage 🚀

Add it to your plugins in `vite.config.ts`:

```ts
import { defineConfig } from 'vite'
import manifestSRI from 'vite-plugin-manifest-sri'

export default defineConfig({
  plugins: [
    manifestSRI(),
  ],
})
```

Note that the [`build.manifest`](https://vitejs.dev/config/#build-manifest) option
must be enabled in order to generate a `manifest.json` file ([Vite Ruby] enables it by default).

### With [Vite Ruby] 💎

Experimental support is [available](https://github.com/ElMassimo/vite_ruby/issues/176#issuecomment-1015920689), you can try it now by explicitly adding `4.0.0.alpha1` to your `Gemfile`:

```ruby
gem 'vite_rails', '~> 4.0.0.alpha1'
```

## Configuration ⚙️

The following options can be provided:

- <kbd>algorithms</kbd>
  
  Hashing algorithms to use when calculate the integrity hash for each asset.

  __Default:__ `['sha384']`

  ``` js
  manifestSRI({ algorithms: ['sha384', 'sha512'] }),
  ``` 

## Acknowledgements

The following plugins might be useful for Vite apps based around an `index.html` file:

- [`rollup-plugin-sri`](https://github.com/JonasKruckenberg/rollup-plugin-sri)
- [`vite-plugin-sri`](https://github.com/small-tech/vite-plugin-sri)

## License

This library is available as open source under the terms of the [MIT License](https://opensource.org/licenses/MIT).

---
_Source: https://npm.io/package/vite-plugin-manifest-sri · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
