Include archive's digest and PGP signature in release announcement
Release announcement should be improved to include the archive's digest and PGP signature.
See for example TZDB announcement.
https://mm.icann.org/pipermail/tz-announce/2021-October/000069.html
For latest release, it could be:
c8d6681e38c56f172892c85ddc0852e1fd4b53b4209e7f4ebf17f7e2eae71d92 libxml2-2.9.12.tar.gz
-----BEGIN PGP SIGNATURE-----
iQEzBAABCAAdFiEE20ZoG7ka3OoXD6LUFViLJllr6l0FAmCddwQACgkQFViLJllr 6l11LQgAioRTdfmcC+uK/7+6HPtF/3c5zkX6j8VGYuvFBwZ0jayqMRBAl++fcpjE JUU/JKebSZ/KCYjzyeOWK/i3Gq77iqm3UbZFB85rqu4a5P3gmj/4STWVyAx0KU3z G3jKqDhJOt7c0acXb5lh2DngfDa1dn/VGcQcIXsqplNxNr4ET7MnSJjZ3nlxYfW2 E5vWBdPCMUeXDBl6MjYvw9XnGGBLUAaEJWoFToG6jKmVf4GAd9nza20jj5dtbcJq QEOaSDKDr+f9h2NS8haOhJ9vOpy52PdeGzaFlbRkXarGXuAr8kITgATVs8FAqcgv MoVhmrO5r2hJf0dCM9fZoYqzpMfmNA== =KfJ9 -----END PGP SIGNATURE-----
It would be great to also include the commit from which the release archive was generated, such as:
commit b48e77cf tag v2.9.12
PS: http://xmlsoft.org/news.html wasn't updated for v2.9.12 (given the changes between v2.9.11 and v2.9.12 ;)