Earlier quoted context omitted.
This is all pointless handwaving; the update package itself is signed and will not install if tampered with, regardless of TLS certs used to download it. TLS is not used to authenticate the update.
Ah, right. That makes sense. If only it was mentioned on the download page!
Yes. That's the marketing page explaining how Gatekeeper works, but yes, in the end it's a feature of Gatekeeper that makes it harder for you to open unsigned packages and impossible to open packages with a broken signature.
So even when you don't know about pkgutil (most people don't), Gatekeeper will still help you.