This is a legitimate case as it's happened to other projects in the past.
FWIW the macOS pkg you download is signed.