It mostly won't help, that's why I said it would be a nice-to-have as opposed to a big deal. (That being said, it shouldn't be a lot of work either, so hey, if you find the time I won't complain.

)
And I'm sure the distros are happy enough that the source tarballs are now available over HTTPS. It's not as though there isn't a lot of other software that doesn't come with GPG signing either...