Third-party disclosure
Visitors and maintainers should be able to tell what depends on someone else.
Third-party disclosure covers packages shipped in the production build, services contacted at runtime, embedded media, analytics endpoints, hosted forms, and any browser-side code that is not owned by the site.
Rule#
Disclose third-party code and services that affect privacy, licensing, runtime behaviour, availability, or maintenance.
Disclose when#
- a package ships in the production JavaScript or CSS bundle
- browser code contacts a third-party service
- an embed loads remote code, media, frames, or tracking surfaces
- analytics, search, forms, or comments use an external service
- a font, image, or icon is not locally hosted
- a legal, security, or attribution page claims an inventory
Do not over-disclose#
Build-time tooling does not need visitor-facing disclosure unless its output creates a runtime dependency or a licensing obligation. Internal scripts, formatters, and test tools belong in implementation documentation or repository metadata.
Inventory#
The inventory should distinguish:
- packages present only at build time
- packages shipped in production
- packages that execute in the browser
- services contacted from the browser
- services contacted from the Worker or server side
Maintenance#
Update disclosure when adding or removing runtime packages, analytics behaviour, embeds, external assets, or Cloudflare products that change visitor-visible behaviour.