GHC downloads are unsigned
I recently came across a feature that is patched in 7.6 but not in 7.4; cause to upgrade. The Haskell website has binary downloads, ie http://www.haskell.org/ghc/download_ghc_7_6_1\#x86_64linux but there are no SHA1 hashes or GPG signatures.
This may seem like busy work, but it's important to know who is building software and how it was built. Would it be possible to first of all post md5sums or sha1sums of the builds, and then down the road get that file GPG signed by someone responsible for the process?
Not sure where best to file this; sorry for noise if this is the wrong place.