You'll notice
The cached policy-limits response now carries a signature that is checked on load, so a tampered cache file is rejected.
Fetched policy-limits responses now carry a signature derived from response headers, persisted alongside the cache file and checked via a signed-cache verification path on load. This guards against a tampered policy-limits cache file being loaded.