Detached signature (common for downloads/releases):
Verify a file + signature:
gpg --verify file.sig file
Clear-signed message (text):
Verify clearsigned text:
gpg --verify statement.txt.asc
What a “Good signature” means
Integrity: the content did not change after it was signed.
Key control: the signer controlled the private key corresponding to this public key.
Identity binding is up to the verifier: confidence comes from cross-checking this fingerprint with copies published via trusted sources (this page, the author’s website, GitHub org profile, official social accounts, etc.).
Qhash proof-of-existence (public blockchain anchoring): Qhash anchors the hash of a signed file on a public blockchain, creating a tamper-evident timestamp that may have legal/probative value as evidence of prior existence and authorship/priority.