The #curl release on GitHub is now marked as "immutable" and there's even something they call "release attestation" there now.
Just remember that the curl canonical releases are the signed tarballs uploaded by me. Reproducible, so you can verify them at will to not contain bad things. Signed to prove I did them.
Made with love and care, I promise.
If you have a fediverse account, you can quote this note from your own instance. Search https://mastodon.social/users/bagder/statuses/115495889457886682 on your instance and quote it. (Note that quoting is not supported in Mastodon.)
