What’s your alternative?
A mirrored package manager, where signature and executable are always grabbed from different sources.
Like apt, dnf, and others.
Pretty sure my apt sources have the signing and package pointing to the same place
If you have more than a single source, then apt will already be checking this for you.
The default is more than a single source.
All of mine point to like somethingsomething.ubuntu.com
If it points to mirror.ubuntu.com, it'll be mirroring at host end, instead of inside apt. But as apt does do resolution to a list, it'll be fetching from multiple places at once.