Generally, this process is not for the consumer.
Some power users will go in and verify based on provided instructions from the depths.
@78ce6faa…f026307d brings in sig verification as a core part of the UX.
Zapstore is more like Google Play; it's for Android app downloads. Different sector.
I'm signing git commits and git commit tags, inside of the source repo.