I can't verify the validity and the authorship of the release files currently. You can do, e.g.: ``` $ sha256sum --tag * > SHA256SUMS $ gpg --detach-sign SHA256SUMS ``` And then upload both `SHA256SUMS` and `SHA256SUMS.sig`.