Release signing depends on protecting signing keys

A signing key that lives in the CI system is available to whoever compromises the CI system.

That is the whole difficulty. Keys in hardware, with separate approval to use them, provide real assurance. Keys in an environment variable provide a signature that anybody with pipeline access can produce, which proves the pipeline ran rather than that anybody approved the release.

More on CI/CD security