Skip to content

Embedding a SVG #21945

Answered by nadiajoyce
NNTin asked this question in New to GitHub
Discussion options

You must be logged in to vote

@nntin Sorry for any confusion. Let me see if I can explain a little better.

We return a content-type of text/plain for SVG images served from raw.githubusercontent.com. We do that to prevent any JS execution. The reason we don’t want to have JS executed with raw.githubusercontent.com is because it might be possible for someone to exploit our site through that mechanism. We generally want to eliminate all security problems no matter how far fetched they are. I hope you understand why I can’t go into the details, and I hope you trust we have a good reason for doing so.

In any case I’ve shared your feedback with our team about the problems this creates in situations like yours.

Replies: 5 comments

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Answer selected
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
3 participants