verify https assets with a public transparency log
Why do you think that https://github.com/sigstore/rekor is a good alternative to tl
verify https assets with a public transparency log
Why do you think that https://github.com/sigstore/rekor is a good alternative to tl