My current trust anchor is:
=> LibrePGP's
=> keyfile
$ gpg --auto-key-locate dane --locate-keys stargrave@stargrave.org
$ gpg --auto-key-locate wkd --locate-keys stargrave@stargrave.org
$ gpg --auto-key-locate wkd --locate-keys stargrave@gnupg.net
=> PGP keyring with previously used keys
But it lacks post-quantum resistant signing algorithms.
So there are more simple and advanced KEKS/CM below.
=> KEKS/CM
I used to sign software tarballs with OpenPGP/LibrePGP keys.
Later I moved to using of OpenSSH ssh-keygen's signing capabilities.
=> Fingerprints/keys
=> its detached PGP signature
=> its detached OpenSSH signature
=> its detached KEKS/CM signature
OpenSSH keys:
=> keys/master.git.stargrave.org_ed25519.pub
=> keys/master.git.stargrave.org_mldsa44-ed25519.pub
=> keys/slave.git.stargrave.org_ed25519.pub
=> keys/slave.git.stargrave.org_mldsa44-ed25519.pub
=> keys/bass@stargrave.org.pub
=> keys/dsc@stargrave.org.pub
=> keys/go.stargrave.org.pub
=> keys/gocheese@stargrave.org.pub
=> keys/gogost@stargrave.org.pub
=> keys/goredo@stargrave.org.pub
=> keys/gostls13@stargrave.org.pub
=> keys/keks@stargrave.org.pub
=> keys/meta4ra@stargrave.org.pub
=> keys/pyderasn@stargrave.org.pub
=> keys/pygost@stargrave.org.pub
=> keys/releases@nncpgo.org.pub
=> keys/stargrave@stargrave.org.pub
=> keys/tofuproxy@stargrave.org.pub
=> keys/vors@stargrave.org.pub
KEKS/CM keys:
=> keys/bass@stargrave.org.cm
=> keys/gocheese@stargrave.org.cm
=> keys/gogost@stargrave.org.cm
=> keys/goredo@stargrave.org.cm
=> keys/gostipsec@stargrave.org.cm
=> keys/gostls13@stargrave.org.cm
=> keys/keks@stargrave.org.cm
=> keys/meta4ra@stargrave.org.cm
=> keys/pyderasn@stargrave.org.cm
=> keys/pygost@stargrave.org.cm
=> keys/releases@nncpgo.org.cm
=> keys/stargrave@stargrave.org-kem.cm
=> keys/stargrave@stargrave.org-sig.cm
=> keys/tofuproxy@stargrave.org.cm
=> keys/vors@stargrave.org.cm