to give users an extra sense of security that they have a real, untampered-with download.
Example: See the consul_0.6.4_SHA256SUMS file at https://releases.hashicorp.com/consul/0.6.4/
Would be great if you sign the file with a GPG key -- e.g.: consul_0.6.4_SHA256SUMS.sig
to give users an extra sense of security that they have a real, untampered-with download. Example: See the consul_0.6.4_SHA256SUMS file at https://releases.hashicorp.com/consul/0.6.4/ Would be great if you sign the file with a GPG key -- e.g.: consul_0.6.4_SHA256SUMS.sig