    All merge submissions must be signed with a trusted PGP key, and Bitcoin Core has a continuously integrated system to check each submitted PGP key. Although we know who the keys are in, they are not absolutely secure because they can be stolen or cracked. Therefore, submitting a key to sign is not a perfect security scenario, they just make it more difficult for attackers to add code at will.