GPG Signature support removed from PyPI

As previously mentioned, you can certainly publish detached OpenPGP
signatures of all your sdists/wheels to a separate site. If users
already need to do out-of-band work to determine that they trust
your signing keys then also going somewhere else to download the
signatures (from your project site for example) isn’t a huge
stretch.

This was the compromise we arrived at long ago for the OpenStack
community’s many projects. Downstream redistributors (like those
doing packaging work in GNU/Linux distributions) know where to find
the signatures from our release automation in order to make sure
that what they retrieved from PyPI hasn’t been tampered with
at/after publication.