Re: [w3c/ServiceWorker] Preventing server-forced updates (#822)

>SRI cannot help this use case as SRI just uses hashes, not asymmetric signatures. SRI is only useful for cross-origin security.

Not true, as SRI can be used to specify an immutable bootloader which implements the asymmetric signature verification.

-- 
Reply to this email directly or view it on GitHub:
https://github.com/w3c/ServiceWorker/issues/822#issuecomment-1610899945
You are receiving this because you are subscribed to this thread.

Message ID: <w3c/ServiceWorker/issues/822/1610899945@github.com>

Received on Wednesday, 28 June 2023 07:20:39 UTC