I think apt checks signatures.
You only need to be careful when adding a new repo to verify the pubkey there.
Login to reply
Replies (1)
I use apt and dnf. They all do some form of verification. Verifying repo pubkeys UX is bad, and there is no second layer of defence (e.g. malware makes it into a repo, not uncommon)