wget http(s)://... | tar x
make
package
sign_with_gpg
upload_to_ftp
Only if a package maintainer gets involved there is a chance that release signatures are actually verified. But even then, a whole lot of upstream projects just don't sign their releases. Some distros don't sign their packages, either. Or even their ISOs (iirc Linux Mint only started doing this fairly recently).Also, "web of trust" only works for a tiny subset of people. If I'm a "lone wolf" FOSS developer, my key won't be signed by anyone, there won't be any WoT to verify. Downstream packagers just have to swallow that or TOFU.