My current trust anchor is:
    => LibrePGP's
    => keyfile

    $ gpg --auto-key-locate dane --locate-keys stargrave@stargrave.org
    $ gpg --auto-key-locate  wkd --locate-keys stargrave@stargrave.org
    $ gpg --auto-key-locate  wkd --locate-keys stargrave@gnupg.net

=> PGP keyring with previously used keys

But it lacks post-quantum resistant signing algorithms.
So there are more simple and advanced KEKS/CM below.
=> KEKS/CM

I used to sign software tarballs with OpenPGP/LibrePGP keys.
Later I moved to using of OpenSSH ssh-keygen's signing capabilities.

=> Fingerprints/keys
=> its detached PGP signature
=> its detached OpenSSH signature
=> its detached KEKS/CM signature

OpenSSH keys:
    => keys/master.git.stargrave.org_ed25519.pub
    => keys/master.git.stargrave.org_mldsa44-ed25519.pub
    => keys/slave.git.stargrave.org_ed25519.pub
    => keys/slave.git.stargrave.org_mldsa44-ed25519.pub
    => keys/bass@stargrave.org.pub
    => keys/dsc@stargrave.org.pub
    => keys/go.stargrave.org.pub
    => keys/gocheese@stargrave.org.pub
    => keys/gogost@stargrave.org.pub
    => keys/goredo@stargrave.org.pub
    => keys/gostls13@stargrave.org.pub
    => keys/keks@stargrave.org.pub
    => keys/meta4ra@stargrave.org.pub
    => keys/pyderasn@stargrave.org.pub
    => keys/pygost@stargrave.org.pub
    => keys/releases@nncpgo.org.pub
    => keys/stargrave@stargrave.org.pub
    => keys/tofuproxy@stargrave.org.pub
    => keys/vors@stargrave.org.pub

KEKS/CM keys:
    => keys/bass@stargrave.org.cm
    => keys/gocheese@stargrave.org.cm
    => keys/gogost@stargrave.org.cm
    => keys/goredo@stargrave.org.cm
    => keys/gostipsec@stargrave.org.cm
    => keys/gostls13@stargrave.org.cm
    => keys/keks@stargrave.org.cm
    => keys/meta4ra@stargrave.org.cm
    => keys/pyderasn@stargrave.org.cm
    => keys/pygost@stargrave.org.cm
    => keys/releases@nncpgo.org.cm
    => keys/stargrave@stargrave.org-kem.cm
    => keys/stargrave@stargrave.org-sig.cm
    => keys/tofuproxy@stargrave.org.cm
    => keys/vors@stargrave.org.cm