Compare a jar file with its corresponding signed jar. The logic for this is complex, and best explained in the source itself. Essentially if either file doesn't exist, or the destfile has an out of date timestamp, then the return value is false. If we are signing ourself, the check {@link
(File jarFile, File signedjarFile)
source not stored for this graph (policy: none)