Unfortunately the GPG signing is worthless because there's no way of attaching trust to each key. So each package has been signed, but anyone could have issued the keys, so an attacker could easily do the same.
Also, not all artifacts have sources and javadoc. Most do but some certainly don't.