# Tracker versioning and Subresource Integrity

> How the hosted pa.js tracker is updated, and how to self-host a pinned copy with a Subresource Integrity (SRI) hash when your security policy requires it.

## One stable URL

`https://privatusanalytics.com/js/pa.js` always serves the current tracker. Updates
are backwards compatible: attributes, the JavaScript API and the request
format don't change in breaking ways under the same URL. Tracker releases
are listed in the changelog and appear as automatic
[notes](/docs/dashboard/notes) on your charts, so you can see when a
change could affect your numbers.

## Subresource Integrity (SRI)

SRI pins a script to an exact hash. Because `pa.js` is updated in place,
an `integrity` attribute on the hosted URL would break the tracker at the
next release. If your security policy requires SRI:

1. **Self-host a copy** of the tracker (and any modules you use) from your
   own domain. The source is MIT licensed and published with every release.
   The npm package `@privatus/tracker` doesn't pin the tracker. It's a
   loader that injects the hosted `pa.js` at runtime (or the `src` you
   give it) and has no `integrity` option, so its version pins the loader
   code only.
2. Compute the hash:

   ```sh
   curl -s https://privatusanalytics.com/js/pa.js -o pa.js
   echo "sha384-$(openssl dgst -sha384 -binary pa.js | openssl base64 -A)"
   ```

3. Reference your copy with the hash and point hits at us with
   `data-api`:

   ```html
   <script defer src="/assets/pa.js"
           integrity="sha384-…" crossorigin="anonymous"
           data-site="pa_YOURSITEID"
           data-api="https://privatusanalytics.com"></script>
   ```

Modules are loaded from `data-api`, not from your copy's location, and
they are loaded without an `integrity` attribute. So with the setup above,
any module you add in `data-modules` (for example `vitals` or `clicks`)
comes from `https://privatusanalytics.com/js/` and is not covered by your SRI hash.
If your policy requires every script to be pinned, leave out
`data-modules` or set it to `engage` only (engagement tracking is built
into `pa.js` and loads no extra file).

Update your copy when you want new tracker features. Old versions keep
working.
