Docs
Navegar pela documentação

Tracker versioning and Subresource Integrity

How the hosted pa.js tracker is updated, and how to self-host a pinned copy with a Subresource Integrity (SRI) hash when your security policy requires it.

Ver como Markdown

One stable URL#

https://privatusanalytics.com/js/pa.js always serves the current tracker. Updates are backwards compatible: attributes, the JavaScript API and the request format don't change in breaking ways under the same URL. Tracker releases are listed in the changelog and appear as automatic notes on your charts, so you can see when a change could affect your numbers.

Subresource Integrity (SRI)#

SRI pins a script to an exact hash. Because pa.js is updated in place, an integrity attribute on the hosted URL would break the tracker at the next release. If your security policy requires SRI:

  1. Self-host a copy of the tracker (and any modules you use) from your own domain. The source is MIT licensed and published with every release. The npm package @privatus/tracker doesn't pin the tracker. It's a loader that injects the hosted pa.js at runtime (or the src you give it) and has no integrity option, so its version pins the loader code only.
  2. Compute the hash:
sh
   curl -s https://privatusanalytics.com/js/pa.js -o pa.js
   echo "sha384-$(openssl dgst -sha384 -binary pa.js | openssl base64 -A)"
  1. Reference your copy with the hash and point hits at us with data-api:
html
   <script defer src="/assets/pa.js"
           integrity="sha384-…" crossorigin="anonymous"
           data-site="pa_YOURSITEID"
           data-api="https://privatusanalytics.com"></script>

Modules are loaded from data-api, not from your copy's location, and they are loaded without an integrity attribute. So with the setup above, any module you add in data-modules (for example vitals or clicks) comes from https://privatusanalytics.com/js/ and is not covered by your SRI hash. If your policy requires every script to be pinned, leave out data-modules or set it to engage only (engagement tracking is built into pa.js and loads no extra file).

Update your copy when you want new tracker features. Old versions keep working.