Also, really, the TLDR should be just use TUF + in-toto already.
[1] https://www.datadoghq.com/blog/engineering/secure-publicatio...