Add design for split source+binary upload signing

Part of #944 (closed).

/cc @hertzog

Merge request reports

Loading