residc test builds the file’s test blocks into a test binary and runs
it (Testing).
residc keygen [dir] writes an Ed25519 key pair (resid-ed25519.key,
readable only by its owner, and .pub), by default in keys/.
residc verify <binary> checks the provenance signature, the code hash
and every sidecar present, then reports evidence and attestation apart
and names the keyring the key came from; --anchored accepts only the
install’s keyring and --sources DIR re-hashes the sources
(Provenance).
residc lsp runs the language server on stdin/stdout
(Editor).