krites-models v0.1.1

Dual-signed release (krites spec 0034): checksums.txt carries signatures from
both the v1 key (old account, decommissioning) and the v2 key (prod), so a krites
binary trusting either generation can verify it.

Also activates the producer fix folding provenance.json into checksums.txt, so
provenance is covered by the signature rather than cross-checked.