Details are available here.
It is essential that you verify the integrity of any downloaded files using the PGP or MD5 signatures. For more information on signing artifacts and why we do it, check out the Release Signing FAQ.
The PGP signatures can be verified using PGP or GPG. First download the KEYS as well as the asc signature file for the artifact. Make sure you get these files from the main distribution directory, rather than from a mirror. Then verify the signatures using e.g.:
$ pgpk -a KEYS $ pgpv deltaspike-project-1.0.3-source-release.zip.asc
$ pgp -ka KEYS $ pgp deltaspike-project-1.0.3-source-release.zip.asc
$ gpg --import KEYS $ gpg --verify deltaspike-project-1.0.3-source-release.zip.asc