Check out this list of development/release practices for #curl.

This is table stakes for being a responsible player in the open-source infrastructure game.

https://curl.se/docs/verify.html

curl - Verify