a) ensure this exact binary/script is GPG signed by someone I ostensibly trust
b) ensure it's not been tampered with by a MitM between the hosting server and my computer
This reduces my risk exposure to "creator of software X (or distro packager Y) has turned rogue", which is many orders of magnitude less likely than "website of software X got pwned, or someone is MitM-ing me".