Would it be possible to sign the releases here like we do for bazel itself? e.g. https://github.com/bazelbuild/bazel/releases/download/8.4.2/bazel-8.4.2-linux-x86_64 and https://github.com/bazelbuild/bazel/releases/download/8.4.2/bazel-8.4.2-linux-x86_64.sig which is generated using the bazel GPG key: https://bazel.build/bazel-release.pub.gpg