We're currently working on a way to update the containers we're using for Dangerzone without having to issue new releases. In order to do that, we push new container images to a container registry, and sign them with an hardware key. In addition, we want to do the verification part …