Celix releases are signed using a GPG key, and the key is uploaded to the Celix KEYS file.
Add a section to the download page to make it easier for users of Celix to verify the integrity of the downloaded file.
Possibly examples from another project can be used. For example, Apache Airflow describes how to verify a release on the following page:
https://airflow.apache.org/docs/apache-airflow/2.3.3/installation/installing-from-sources.html#release-integrity