Import `keys/pgp` automatically when verifying a package

We have keys/pgp now thanks to this change in commitpkg. But we do not yet use the keys to verify sources=() automatically.