The packages are built via the CI pipeline (at least I think), thus this would have to be included somehow. Without a paid CI account, it might be impossible to use a private key to sign packages via a public pipeline.