Some Apple signatures expiring on October 24, 2019
derflounder.wordpress.com
derflounder.wordpress.com
For EFI (per the screenshot) I wonder if they are looking to protect against the risk of an update that introduces an EFI vulnerability. Unless Apple is checking a certificate revocation list (or similar) then an attacker could apply that vulnerable update. Letting it expire sets a limit for how long it can be exploited. Just a guess.