Right now, you can only get the signed release hashes at https://getmonero.org/downloads/hashes.txt
If you archive the old release hashes.txt and give each release hashes.txt their own URL based on their version name like getmonero.org/downloads/v0.18.5.0/hashes.txt then it would be possible to verify the upstream signatures in an automated/tansparent way using gentoo's "verify-sig" functionality.
Right now, you can only get the signed release hashes at https://getmonero.org/downloads/hashes.txt
If you archive the old release hashes.txt and give each release hashes.txt their own URL based on their version name like getmonero.org/downloads/v0.18.5.0/hashes.txt then it would be possible to verify the upstream signatures in an automated/tansparent way using gentoo's "verify-sig" functionality.