The subkey used for signing releases recently expired (which is ignored when verifying with gpg). The primary key would expire soon. Therefore this commit adds a key with extended expiry date of both primary key and subkey.
This allows getting the hash of the latest (or some other) release using github releases and gpg verification.