drop maven artifact + asc signature export · parse gpg key id + signature validity hints · runs locally
drop maven artifact + asc signature export · local only
heuristic screener · vendor schema varies · not definitive proof