Third-party disclosure

Visitors and maintainers should be able to tell what depends on someone else.

Third-party disclosure covers packages shipped in the production build, services contacted at runtime, embedded media, analytics endpoints, hosted forms, and any browser-side code that is not owned by the site.

Rule#

Disclose third-party code and services that affect privacy, licensing, runtime behaviour, availability, or maintenance.

Disclose when#

  • a package ships in the production JavaScript or CSS bundle
  • browser code contacts a third-party service
  • an embed loads remote code, media, frames, or tracking surfaces
  • analytics, search, forms, or comments use an external service
  • a font, image, or icon is not locally hosted
  • a legal, security, or attribution page claims an inventory

Do not over-disclose#

Build-time tooling does not need visitor-facing disclosure unless its output creates a runtime dependency or a licensing obligation. Internal scripts, formatters, and test tools belong in implementation documentation or repository metadata.

Inventory#

The inventory should distinguish:

  • packages present only at build time
  • packages shipped in production
  • packages that execute in the browser
  • services contacted from the browser
  • services contacted from the Worker or server side

Maintenance#

Update disclosure when adding or removing runtime packages, analytics behaviour, embeds, external assets, or Cloudflare products that change visitor-visible behaviour.