@sophieschmieg @neverpanic @soatok we do not lack good cryptographic libraries, but a good signature format schemes that works fully offline and does not try to impose complicated/online setups both for signing and verification.
I find sigstore exceedengly complicated for simple software signing cases for example.
I do not mind additional transparency ledgers or assurances if they are additive properties.
Algoritmic agility and design that makes it easy to use with HSMs is a must.