Nothing on a release is signed. Someone who downloads siltide-linux-amd64 can compare it against checksums.txt, which is only as trustworthy as the page that served both.
A detached signature per asset, and a KEYS file at the repository root holding the current key and the retired ones so older releases stay verifiable, would let a download be verified against a key that came from this repository rather than a keyserver search, where anyone can upload a key under any name. The verify step then belongs in the install instructions, and a stable release should only go public once signing has succeeded.
Nothing on a release is signed. Someone who downloads siltide-linux-amd64 can compare it against checksums.txt, which is only as trustworthy as the page that served both.
A detached signature per asset, and a KEYS file at the repository root holding the current key and the retired ones so older releases stay verifiable, would let a download be verified against a key that came from this repository rather than a keyserver search, where anyone can upload a key under any name. The verify step then belongs in the install instructions, and a stable release should only go public once signing has succeeded.