Authenticate a tarball through a signed tag in a git repository (with reproducible builds).
Blog post: https://vulns.xyz/2022/05/auth-tarball-from-git/ Source code: https://github.com/kpcyrd/auth-tarball-from-git Pretty interesting, could be useful for guix.