Page MenuHomePhabricator

ores.wikimedia.org/ui/ is loading resources from external sites
Closed, DuplicatePublic

Description

<link rel="stylesheet" href="https://wikimedia-ui.wmflabs.org/MW/mediawiki.min.css">
<link rel="import" href="https://munmay.github.io/WikimediaUI/MW/elements.html">
<script src="https://fontastic.s3.amazonaws.com/Sr6GbqfKhL8VvZWw23WzLN/icons.js"></script>
<script src="https://ajax.googleapis.com/ajax/libs/jquery/1.11.3/jquery.min.js"></script>
<script src="https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/3.3.5/js/bootstrap.min.js"></script>
<!-- IE10 viewport hack for Surface/desktop Windows 8 bug -->
<script src="https://wikimedia-ui.wmflabs.org/bootstrap-3.3.5-dist/js/ie10-viewport-bug-workaround.js"></script>
<script src="https://raw.githubusercontent.com/kylefox/jquery-tablesort/master/jquery.tablesort.min.js"></script>

The last one that is unversioned and loading directly from github is extremely scary.