Skip to main content

Django SRI

CI PyPI PyPI - Python Version PyPI - Status PyPI - License

Subresource Integrity for Django.

Installation

pip install django-sri

And add sri to your INSTALLED_APPS.

Usage

Template Tags

django-sri is intended to primarily be used through template tags:

{% load sri %}

<!-- Add the required integrity attributes to the relevant tag -->
<link rel="stylesheet" href="{% static 'index.css' %}" {% sri_attrs 'index.css' %} />
<script src="{% static 'index.js %}" {% sri_attrs 'index.js' %}></script>

<!-- Or, get the integrity value directly -->
<script src="{% static 'index.js %}" integrity="{% sri_integrity 'index.js' %}" crossorigin="anonymous"></script>
<link rel="stylesheet" href="{% static 'index.css' %}" integrity="{% sri_integrity 'index.css' %}" crossorigin="anonymous" />

Note: By default, sri_attrs does not output when DEBUG is True, as static files change a lot during local development. To override this, set USE_SRI to True. sri_integrity always outputs.

When outside DEBUG (or forced using USE_SRI), hashes are cached using an lru_cache.

Algorithms

The SRI standard supports 3 algorithms: SHA256, SHA384 and SHA512. By default, SHA256 is used. To override this, supply an additional algorithm argument to the template tag:

{% load sri %}

{% sri_integrity "index.js" algorithm="sha512" %} <!-- Will output "integrity='sha512-...'" -->

The default algorithm can be changed by setting SRI_ALGORITHM to the required algorithm.

API

Outside of templates, the relevant integrity values can be retrieved using get_sri or get_sri_of_static.

get_sri accepts the path to any file, whereas get_sri_of_static resolves static files similar to {% static %}.

from pathlib import Path
from sri import get_sri, get_sri_of_static

get_sri(Path("/path/to/myfile.txt"))  # "sha256-..."
get_sri(Path("/path/to/myfile.txt"), "sha512")  # "sha512-..."

get_sri_of_static("index.js")  # "sha256-..."
get_sri_of_static("index.js", "sha512")  # "sha512-..."

"Does this work with whitenoise or alike?"

Yes. django-sri outputs the static file URL in the same way the builtin static template tag does. This means the correct cachebusted URLs are output.

When using a manifest STATICFILES_STORAGE, django-sri will automatically retrieve the hashed and post-processed file as opposed to the original.

jinja2

Support for jinja2 templates is provided using the sri.jinja2.sri extension, which adds the documented Django template tags as global functions. These functions work identically to the Django template versions.

Release files for django-sri 1.0.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for django-sri 1.0.0
File Size Uploaded
django_sri-1.0.0.tar.gz 7.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for django-sri 1.0.0
File Interpreter ABI Platform
django_sri-1.0.0-py3-none-any.whl Python 3 none any Details

Total release size: 13.3 kB

Release files / django_sri-1.0.0.tar.gz

Download URL django_sri-1.0.0.tar.gz
Size 7.3 kB
Tags Source
SHA-256 checksum
How to use checksums
840b0f8b368dd1442c895c69e87206bfc727fe3a04477b733ba715f3c1f71208
BLAKE2b-256 checksum
How to use checksums
dea27f0545733deff53778bbec6331a5fbc7f11de3c9a8f06b5633e3eb05c597
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.

Transparency log

Release files / django_sri-1.0.0-py3-none-any.whl

Download URL django_sri-1.0.0-py3-none-any.whl
Size 6.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
9a1e52cd99678b635f29954789d473c36ab9216d48660a02b44dc25c1f9ced46
BLAKE2b-256 checksum
How to use checksums
c76943b6c71b1a91702ec6bfe5c9d32918ec234fc30d50f77fd8c5845bf38f86
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

1.0.0 This release

2 release files

0.8.0

2 release files

0.7.0

2 release files

0.6.0

2 release files

0.5.0

2 release files

0.4.0

2 release files

0.3.0

2 release files

0.2.0

1 release file

0.1.2

1 release file

0.1.1

1 release file

0.1.0

1 release file

0.0.0

1 release file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page