@dalias @leoluk @GossiTheDog at the very least, lets check GPG signatures rather than just SHA checksums