Where are the cryptographic signatures? (SHA256SUMS, Release.gpg)

With regard to an equivalent of source signing, that’s a little murkier. The source hashes end up in nixpkgs, but the nixpkgs ‘channel’ doesn’t seem to be explicitly signed; various bits of discussion I found: