An exposed apt signing key and how to improve apt security
blog.cloudflare.com
blog.cloudflare.com
Still a bit ugly depending on the point of view you take but a 3rd party vendor can just tell the user to download this file and store it in /etc/apt/sources.list.d/ which should make that whole thing a bit more frictionless.