Supposedly you would get the GPG key from somewhere else, ideally through a web of trust, although I find it hard to do in practice
You also typically download it from a different place than the storage location of the signed binary artifacts. This means that an adversary will have a hard time trying to replace a public key and remain undetected.