How do you verify that nobody is holding the original developer at gunpoint making them sign their compromised software with their real key?
The point I’m trying to make: At some point, you have to trust something which you can not feasibly verify.
For most cases the github repo and an occasional look on a relevant newsfeed is good enough. If it’s not good enough for yours, the first question still stands.
dammn perverts those devs!