Earlier quoted context omitted.
Releases have to be PGP signed, snapshot's don't. How many people do you know that verify PGP signatures of their artifacts? Do you?
Yes, we verify signatures at our middleware repository cache.
Really? Impressive! Where do you get the public keys? Most projects hosted on Maven Central don't publish them on their website.