The binaries should be built on the CI with GitHub Attestations (https://github.com/actions/attest), not on a maintainer's laptop. The builds should be also reproducible (https://reproducible-builds.org).