* AppImage is already signed - how can we verify it? Should we just sign it with GPG? * Sign the windows packages with GPG as well * Publish the public key on the website * Add verification steps to the documentation