sigillum
Sign and verify release artefacts from the command line, whatever your project is written in. The private key never leaves your KMS, HSM or PEM file.
Matt Cockayne · building in the open since 2012
I'm Matt Cockayne. I build Go and Rust tooling, and the infrastructure that makes a release something you can prove came from you. Twenty years of it, most of it in the parts other people build on.

What I'd look at first
Sign and verify release artefacts from the command line, whatever your project is written in. The private key never leaves your KMS, HSM or PEM file.
FFmpeg in pure Go. No CGO, no install on the box, no temp files: a WASM build over an in-memory filesystem.
The framework the rest of the estate is extracted from. Config, errors, transport, observability and release plumbing that already agree with each other.
If you only read five
Five posts that between them cover most of what this is: how the tooling works, what I think about the industry, and why any of it exists.
Latest
Or take a whole subject
The blog runs newest-first, which is right for reading along and no use at all if you have turned up with a problem. Each of these is one subject, start to finish, in the order it makes sense.

He answers questions about the projects on the Discord, and he is better at it than I am after nine o'clock. Bring a bug, an idea, or a questionable engineering decision.