Security & Privacy•September 10, 2026

W3C Recommends Ed25519 Cryptographic Signatures for Subresource Integrity

The W3C Web Application Security Working Group has standardized asymmetric Ed25519 signature verification for script tags, neutralizing CDN supply-chain attacks.

Official Press Release
CybersecuritySRIW3CCryptographyAppSec

The W3C has published the Subresource Integrity (SRI) Level 2 recommendation, adding native asymmetric cryptographic signature verification (Ed25519) alongside traditional SHA-256 and SHA-384 content hashes.

With signature-based SRI, development teams can authorize trusted publishers using public verification keys. If a third-party CDN or script repository is compromised and serves a modified script that is not signed by the original vendor's private key, the browser automatically blocks script execution.

Compute secure cryptographic hashes for your assets using our client-side Hash Generator on Luminus.

Subscribe for Updates

Get official press announcements and version releases sent directly to your email.

Join Mailing List