In the 2 years since I filed this bug report, it's also started hotlinking a font from google, in addition to now 2 mathjax js files from cloudflare.
The font seems to be packaged in Debian in fonts-paratype. -- see shy jo
signature.asc
Description: PGP signature