Some community-spanning discussion on package signing which might be of interest: https://github.com/package-community/discussions/issues/5
Thanks, very interesting