Look for an RSA signature embedded in the .ZIP file comment given the path to the zip. Verify it matches one of the given public keys. Return VERIFY_SUCCESS, VERIFY_FAILURE (if any error is encountered or no key matches the signature).
source not stored for this graph (policy: none)
nothing calls this directly
no test coverage detected