Code signing

A signature proves an artefact came from a particular key and has not changed since.

Both halves are useful and both depend entirely on the key. If the signing key can be used by the build pipeline without a person involved, then anybody who compromises the pipeline can sign. The strength of the signature is the strength of the protection around the key, which is where it usually falls down.

Checked against the primary source.

More on Software supply chain & DevSecOps