Tamper protection
Enable verification#
Enable Sign package in Advanced / Runtime & locks. Save the report's public key outside the ZIP.
Changed, missing or extra files fail verification.
Verify before shipping#
Use your saved key, not one from a suspicious copy: someone could replace both.
Verification command#
- Save
security.verification.trusted_public_key.spkiandsecurity.build_idfrom your downloaded JSON report. - Keep a trusted copy of
security.verification.verifier_pathoutside future packages. - Unpack the ZIP safely. Use
security.verification.manifest_pathinside that package. Keep only its original files; links are rejected. - Run the trusted verifier:
node trusted-verify.mjs "$MANIFEST_PATH" "$PACKAGE_DIRECTORY" \
"$TRUSTED_SPKI" "$EXPECTED_BUILD_ID"
Use your saved values. Success prints valid: true and exits zero. Never run an untrusted verifier.
Limits#
Signing detects changed files. It does not stop someone copying code or prove which JavaScript a browser runs.
Runtime checks are a separate optional layer.