I believe that you can also embed the key in the Release file with that commit, though I've not checked yet.

This allows TOFU by allowing unathenticated repos during first update; and future updates using keys in release files.

It would also allow repositories to rotate keys if users don't specify signed-by in sources files.

@Conan_Kudo that worked since a couple years already. Have to be local absolute paths, though.

