They are signed with 1024bit DSA with SHA1, every piece of that combination is considered obsolete cryptography nowadays. Even the NIST dictates you shouldn't sign anything new with that.
Signing also doesn't stop serving old-and-vunerable-versions as the latest which is in my opinion a vunerability. Apt also has that vulnerability.