feat: minisign signatures on every release download
Every published file gets a .minisig beside it, in the build folder and
in latest/, signed by the existing ed25519 release key in minisign's
prehashed format. minisign.pub at the root replaces
crates/snowbound/release-key.pub as the one public key, compiled into the
app and quoted in the readme's verify command.
The updater now trusts the archive's size and SHA-256 from the signed
build.json alone; release.py still writes each archive's raw signature
for older apps, which check it.
Assisted-by: claude-opus-5.5
0a185b6b6eclover caruso committed on 10/2/2026, 6:57:55 PMparent9b22f11