Identity binding (GPG), external proof (Sigstore), and public verification URL integrated into a reproducible trust model.
gpg public-key qsp vep git-signing public-verification supply-chain-security sigstore github-verified cryptographic-verification identity-binding stage281 stage283
-
Updated
Apr 20, 2026 - HTML