UAPF packages MAY be signed and MAY include integrity hashes for auditability.
Recommended:
metadata/integrity.yamlwith sha256 checksums of cornerstone artifacts- Package signing using an organization PKI or signing service
This repository does not mandate a specific signing technology.