# Vendored third-party assets Served from this repository rather than a CDN, so the Site does not depend on a third party being reachable and honest at the moment a customer opens it, and so the Content-Security-Policy can name only `'self'` for scripts and workers. ## pdf.js 3.11.174 Used by the by-metre flow to measure and rasterise a PDF sheet in the browser. | File | SHA-256 | |---|---| | `pdf.min.js` | `5b5799e6f8c680663207ac5b42ee14eed2a406fa7af48f50c154f0c0b1566946` | | `pdf.worker.min.js` | `feabdf309770ed24bba31a5467836cdc8cf639c705af27d52b585b041bb8527b` | Downloaded from `https://cdnjs.cloudflare.com/ajax/libs/pdf.js/3.11.174/` and verified against the SRI digests cdnjs publishes for that release: ``` pdf.min.js sha512-q+4liFwdPC/bNdhUpZx6aXDx/h77yEQtn4I1slHydcbZK34nLaR3cAeYSJshoxIOq3mjEf7xJE8YWIUHMn+oCQ== pdf.worker.min.js sha512-BbrZ76UNZq5BhH7LL7pn9A4TKQpQeNCHOo65/akfelcIBbcVvYWOFQKPXIrykE3qZxYjmDX573oa4Ywsc7rpTw== ``` To verify or refresh, compare against that API before replacing anything: ```bash curl -s "https://api.cdnjs.com/libraries/pdf.js/?fields=sri" ``` **Version note.** 3.11.174 is old. It is affected by GHSA-wgrm-67xf-hhpq, whose documented workaround is `isEvalSupported: false`; `dtf-site.html` already passes that, so the known path is closed. Upgrading is worthwhile but is an API change, not a file swap, and belongs with its own browser testing — see `ROADMAP.md` 2.7.