Seems like there could be a use for a distributed service that automatically checks the signature of common downloaded executables --especially for in Microsoft world. It's not enough for vendors to simply put the signature on their website.
Edge has Microsoft SmartScreen[1], Chrome has CAMP[2] / Safe Browsing and Firefox has a system that also uses Google's data[3].
[1] https://technet.microsoft.com/en-us/itpro/microsoft-edge/sec...
[2] https://www.cs.jhu.edu/~moheeb/aburajab-ndss-13.pdf
[3] https://wiki.mozilla.org/Security/Features/Application_Reput...
Edit: I missed that part where you were meant pro actively check against publisher provided signatures. The above systems do that only via looking at the code's embedded signature and indirectly via "wisdom of the crowds" style reputation.
Of course chocolatey itself could be compromised.