Checksums and pgp signatures

Hi,
I’d like to move my current setup to hass.io, and first verify the downloaded image, but I can’t seem to find any checksums or signature anywhere…
Do you guys have any suggestion?
Thanks!

Incase this gets answered in the other thread.

Hi Luneth also I would like to understand how to verify the integrity and authenticity of Home Assistant, but I can’t find the CHECKSUM and CHECKSUM.sign check codes anywhere

Any news? Devs maybe?

Hi, this topic seems to be ignored - what a pitty.

In my case - I have put up KVM version of HA on Debian. Source was downloaded from this page Linux - Home Assistant (home-assistant.io) . List of these releases is located on github , but again without checksum.
I would appreciate checksum on every HAOS instance prepared for download. As well as checksum of Add-on’s visible on trusted web and than logged in HAOS during installation.
Maybe I am wrong and this is somehow possible - than I am sorry and I would appreciate help.

If I am right, than main benefit of having home automation without third party involved (compared to cloud based one) is not possible.

Is it planned? According to this: WTH - Open source project without open roadmap we cannot tell.