Tracker versioning and Subresource Integrity
How the hosted pa.js tracker is updated, and how to self-host a pinned copy with a Subresource Integrity (SRI) hash when your security policy requires it.
One stable URL#
https://privatusanalytics.com/js/pa.js always serves the current tracker. Updates
are backwards compatible: attributes, the JavaScript API and the request
format don't change in breaking ways under the same URL. Tracker releases
are listed in the changelog and appear as automatic
notes on your charts, so you can see when a
change could affect your numbers.
Subresource Integrity (SRI)#
SRI pins a script to an exact hash. Because pa.js is updated in place,
an integrity attribute on the hosted URL would break the tracker at the
next release. If your security policy requires SRI:
- Self-host a copy of the tracker (and any modules you use) from your
own domain. The source is MIT licensed and published with every release.
The npm package
@privatus/trackerdoesn't pin the tracker. It's a loader that injects the hostedpa.jsat runtime (or thesrcyou give it) and has nointegrityoption, so its version pins the loader code only. - Compute the hash:
curl -s https://privatusanalytics.com/js/pa.js -o pa.js
echo "sha384-$(openssl dgst -sha384 -binary pa.js | openssl base64 -A)"
- Reference your copy with the hash and point hits at us with
data-api:
<script defer src="/assets/pa.js"
integrity="sha384-…" crossorigin="anonymous"
data-site="pa_YOURSITEID"
data-api="https://privatusanalytics.com"></script>
Modules are loaded from data-api, not from your copy's location, and
they are loaded without an integrity attribute. So with the setup above,
any module you add in data-modules (for example vitals or clicks)
comes from https://privatusanalytics.com/js/ and is not covered by your SRI hash.
If your policy requires every script to be pinned, leave out
data-modules or set it to engage only (engagement tracking is built
into pa.js and loads no extra file).
Update your copy when you want new tracker features. Old versions keep working.