It would be nice, though, if a site owner could use an offline private key to sign a web bundle, and then instruct browsers to only load their web app if the signature matches its public key.
The key would probably have to be delivered in-band, requiring a TOFU security policy, but that's not so bad.
Ideally the browser would also keep track of which version of the app it loaded last time, and give the user the option of fetching a newer version if one is available, to prevent malicious updates.