And then you find some page on the interweb with instruction to use arbitrary copr repo to install a "fixed" version of something.
pubkey is presented, you press yes (or use -y in the first place). done.
even if you verify the key, what's the point. you can't verify every build, you wouldn't be doing anything else.
