essentially i noticed this pinned comment on the wiki
--> ALWAYS DO A CLEAN BUILD <--
This package will verify the signature of the git tag / commit. Developer keys are available here and instructions are here. See the PKGBUILD to determine which developer key you need.
how do i do this? when i try to install with paru it asks me to import some keys, is that safe to do? thanks.