Changelog can be found here.
Binary release can be found here.
Tarballs are signed using key ID 05D29860D0A0668AAEFB9D691F3C021BECA23821
which can be obtained from a keyserver such as
Import the public key with:
gpg --keyserver hkps:// --recv-keys 05D29860D0A0668AAEFB9D691F3C021BECA23821
In order to verify the tarball with the given signature, do:
gpg --verify <tarball sig file> <associated tarball>