Question re: debian package management security

As a Unix/Linux admin, I've got security questions re: debian's package
management regarding gpg/pgp/otherwise signed packages. Is this the
right contact point, or is there someone in particular I should contact?

Jon Lasser
