http://4ynqnnkbfkq327lqr4kfj2udaki224h4isbpjwj5tagxqcgzu7rv6oqd.onion/tags/debian-watch-does-not-check-openpgp-signature.html
If upstream distributions provides such signatures, please use the pgpsigurlmangle options in this watch file's opts= to
generate the URL of an upstream OpenPGP signature. This signature is
automatically downloaded and verified against a keyring stored in debian/upstream/signing-key.asc Of course, not all upstreams provide such signatures but you could
request them as a way of verifying that no third party has modified the
code after its release (projects such as phpmyadmin, unrealircd,...