Catches tampered package signatures (compromised maintainer supply-chain attack) before they reach CI artifacts.