This demo pins the script with integrity. If the file is tampered, the browser refuses to execute
it and logs an SRI error to the console.
Why it’s good: the browser verifies the fetched file’s hash. Any modification (supply-chain attack, cache poison) causes a hard block.
malicious_cdn/jquery.min.js.