Wax seals for software. I build binaries, I want to sign them, my users want to check the seal. Sigil keeps that part and drops the parts of GPG that have caused me pain over the years: key servers, the web of trust, the agent.
goals
- One command to sign, one to verify
- Detached signatures that travel with the artifact
- Verification that fails loudly, never silently
current status
Shipped. Every public release of the projects on this site carries its seal.