For me CSP is enough because the apps I need to trust only have one hash. So I do it manually. I will try to switch over to SXG trusting a signer is easier than having a list of trusted hashes, do you know if there some way to require/verify it that is visible on mobile?
Web Packaging seems to be vaporware to some extent, and I need something that works now.
Web Packaging seems to be vaporware to some extent, and I need something that works now.