W3C Recommends Ed25519 Cryptographic Signatures for Subresource Integrity
The W3C Web Application Security Working Group has standardized asymmetric Ed25519 signature verification for script tags, neutralizing CDN supply-chain attacks.
The W3C has published the Subresource Integrity (SRI) Level 2 recommendation, adding native asymmetric cryptographic signature verification (Ed25519) alongside traditional SHA-256 and SHA-384 content hashes.
With signature-based SRI, development teams can authorize trusted publishers using public verification keys. If a third-party CDN or script repository is compromised and serves a modified script that is not signed by the original vendor's private key, the browser automatically blocks script execution.
Compute secure cryptographic hashes for your assets using our client-side Hash Generator on Luminus.
Subscribe for Updates
Get official press announcements and version releases sent directly to your email.