localhost is considered a secure context by browsers so service workers will work from there even without https.
One such example is secure cookies.
There's a longer list here: https://web.dev/when-to-use-local-https/
Everything else on that list is you can't test https without https. How could you possibly test mixed content without using https? Http/2 is so tied to TLS that the insecure version that nobody has implemented isn't really the same thing. Etc