@ngraham, I thought that at least
had merit, considering that currently, a rather nondescript error is supplied to the user which isn’t immediately actionable.
I can quite easily imagine this frustrating someone, since on Windows, whether a package is signed or not doesn’t affect installation (unless it’s an MSIX package, in which case there is no way to bypass it, so it’s a moot point, because consequently, nobody distributes them in that state).