docs: remind release maintainers to sign the tarballs and publish their key

......@@ -287,6 +287,11 @@ Pay close attention to the prompts as you might be required to enter
your GPG and SSH passphrase(s) to sign and upload the files,
Ensure that you do sign the tarballs, that your key is mentioned in the
release notes, and is published in `docs/release-maintainers-keys/
Add the sha256sums to the release notes
