WICG / signature-based-sri

Signature-based Resource Loading Restrictions
https://wicg.github.io/signature-based-sri/
Other
20 stars 2 forks source link

Support PGP #13

Closed NL-William closed 2 years ago

NL-William commented 4 years ago

Supporting some known techniques, like PGP-keys, would probably speed up adoption, since there are many tools in place to generate correct fingerprint / integrity-hashes.

AdamMajer commented 2 years ago

PGP is only good at Web-of-Trust (WoT) but it fails in general.