Drop the SSH signatures, that went nowhere. Switch to keyless signatures in public attestation logs, using OIDC-derived identities.