Artifact Attestations–now in public beta
github.blog
github.blog
Then anyone can verify it by checking the signature and contents against the org's public key, which is made available somewhere.
This certainly seems like a UX improvement, and a simpler (and thus safer) key management process.