>>106580938
In Arch Linux, packages are signed by the maintainers, so you can be sure it's fine no matter where you downloaded it from.

https://wiki.archlinux.org/title/Pacman/Package_signing

I imagine it's the same in other distros.