Re: [w3ctag/design-reviews] Signature-Based Integrity. (Issue #1041)

mikewest left a comment (w3ctag/design-reviews#1041)

Thanks for your thoughts. My expectation is that we'll land on initial answers quickly, and hopefully get feedback on their deployability from developers who experiment with the system. I'll bring that feedback back to y'all as it comes.

One thing, though, before deferring this for another day: I was hoping for some higher-level guidance on WICG/signature-based-sri#38. It's a somewhat long thread, but the last two messages (from https://github.com/WICG/signature-based-sri/issues/38#issuecomment-2576937213) reasonably sum up the context. This kind of design question seems generic-enough that it would be helpful for us to come up with a principle we can apply. @martinthomson and I touched on this in WICG/signature-based-sri#44, but I think it would benefit from a little more attention. I'll leave this closed, but I'd appreciate continuing the conversation elsewhere. :)

-- 
Reply to this email directly or view it on GitHub:
https://github.com/w3ctag/design-reviews/issues/1041#issuecomment-2684120230
You are receiving this because you are subscribed to this thread.

Message ID: <w3ctag/design-reviews/issues/1041/2684120230@github.com>

Received on Wednesday, 26 February 2025 07:07:25 UTC