Upstream provides signatures for the source tarballs. Automatically
verify them in %prep. This is one less manual step for maintainers.
The upstream tarballs are signed by Alexey Sokolov, AKA DarthGandalf.
The key was initially taken from Alexey's profile page at
savannah.gnu.org¹. The key was then refreshed from the public
keyservers to pick up changes to the expiration date. Lastly, it was
exported via the following command:
gpg2 --armor --export-options export-minimal --export \
D5823CACB477191CAC0075555AE420CC0209989E > gpgkey-5AE420CC0209989E.asc
¹ https://savannah.gnu.org/users/darthgandalf