Cryptographic signing, verification of software and provenance metadata