<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>构建安全 on PlumePHP</title><link>https://plumephp.com/tags/%E6%9E%84%E5%BB%BA%E5%AE%89%E5%85%A8/</link><description>Recent content in 构建安全 on PlumePHP</description><generator>Hugo</generator><language>zh-CN</language><lastBuildDate>Mon, 28 Sep 2026 12:00:00 +0800</lastBuildDate><atom:link href="https://plumephp.com/tags/%E6%9E%84%E5%BB%BA%E5%AE%89%E5%85%A8/index.xml" rel="self" type="application/rss+xml"/><item><title>Vite 前端安全加固：CSP、依赖供应链与构建产物安全</title><link>https://plumephp.com/vite-security-csp-hardening/</link><pubDate>Mon, 28 Sep 2026 12:00:00 +0800</pubDate><guid>https://plumephp.com/vite-security-csp-hardening/</guid><description>&lt;h2 id="引言"&gt;引言&lt;/h2&gt;
&lt;p&gt;前端安全经常被忽视——直到线上被打穿。Vite 项目的基础设施（构建、依赖、产物）本身就构成攻击面：&lt;strong&gt;依赖被投毒、构建脚本被篡改、产物泄漏源码、内联脚本被注入&lt;/strong&gt;。本文不重复「别写 XSS」的老话，而是聚焦&lt;strong&gt;构建层与配置层&lt;/strong&gt;的安全加固：CSP 的正确配置（含 nonce）、依赖供应链的锁与扫、产物的敏感信息治理，以及开发/生产两套环境的策略差异。目标是让「安全」成为 Vite 工程的一部分，而不是事后补丁。&lt;/p&gt;</description></item></channel></rss>