All commits, tags, and releases are signed by me. Always perform commit, tag, and release verification when using the source code repositories. My personal SSH keys used for signing commits, tags, and releases can be found on the Key webpage.
Commit, tag, and release verification should still be performed when using the main source code repositories, despite them being located on Inferencium servers; they are not a substitution for proper security checks.