syft
syft copied to clipboard
Provide a way to verify release integrity
Today we have a checksum file + signature, however, we do not publish the key. We should either publish the key or replace this mechanism (maybe with a sigstore workflow).