You should consider signing git commits & releases.
Essentially duplicate of #2027.
No, it's not. Signing files (or git commits) and calculating hashes of files to put them in the release notes, are fundamentally different things.
Thus please reopen this issue.
I will have to read about this.
@gorhill The issue can be closed since you're doing it since some time. (Duplicate of #2027)
@Snapy That's right, somehow I missed this one. Thanks.
Most helpful comment
I will have to read about this.