Request for Subresource Integrity (SRI) Hash Support for office.js CDN

Rocktim Raj 0 Reputation points
2025-07-09T11:14:42.42+00:00

Dear Microsoft Team,

I hope this message finds you well.

We are currently integrating the Office.js library as part of our Outlook Add-in and are referencing it via the official Microsoft CDN, as shown below:

<script type="text/javascript" src="https://appsforoffice.microsoft.com/lib/1.1/hosted/office.js"></script>

As part of our organization’s security practices, we use code analysis tools (e.g., SonarQube) that flag this usage due to the absence of a Subresource Integrity (SRI) hash.

If possible, we kindly request your support on the following:

Providing version-specific URLs for office.js, if not already available.

Offering corresponding official SRI hash values for these versions, so they can be safely referenced with integrity checks.

This would greatly help in aligning with internal compliance requirements while continuing to use the script directly from Microsoft's trusted CDN.

Thank you for your continued support and for the valuable tools and libraries you provide. We truly appreciate your efforts and would be grateful for any guidance or updates on this matter.

Warm regards,

Rocktim Rajkumar
Software Engineer at Procore

Microsoft 365 and Office | Development | Office JavaScript API
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.