Describe what should be investigated or refactored
With #4519 completed - zarf now includes BOTH a standard signature (legacy) and a bundle signature (latest) in the zarf package when it is signed.
These are duplicative and zarf should remove the legacy signature after a minimum of 6 releases while providing deprecation notice to users.
This will not remove the ability to verify packages that only contain the legacy signature for backwards compatibility.