-----BEGIN PGP SIGNED MESSAGE-----
...
edit-utils-1.92-pkg.tar.gz
One idea which would allow security minded people to at least be able to
manually verify GPG signatures on packages would be to include an MD5
checksum of the packages in these signed announcements.
Hide the checksums at the bottom of the announcement perhaps?