How to use --verify and --nest in the cloud sign command?
--verify will first check whether the certificate is trusted during the signing process. If it is not trusted, the subsequent signing steps will not be performed.
--nest=false (default) will overwrite the original signature when applying a new signature.