KNF / public recordSecurity / Release keys
Release keys

Trust starts at the artifact boundary.

A digest tells you what changed. A key tells you who signed it. Public signing keys will be published before signed release verification is enabled.

The key directory will include fingerprints, algorithm, status, rotation history, and links to the release process. No fingerprint is shown here until a real key is published.

IndexStatus / scope
AlgorithmNot yet published
FingerprintNot yet published
RotationPolicy forthcoming
StatusNo keys published
+
No public keys published

Release verification material will appear before signed releases.