Shouldn't this be at the end and still be these headers, afaik, none of the headers are signed.
these headers
Well, it's obvious that the signature is not signed, but it should be trusted, as this is the only and authorative source of this information.
Isn't it better to be obvious explicit in the doc as well?
1 new commit added
rebased
All good to me, thanks!
Pull-Request has been merged by pingou