>>107545063
https://wiki.archlinux.org/title/Pacman/Package_signing
Pacman uses GPG so I think you'd do something like this if you wanted to manually verify it:
gpg --verify "abseil-cpp-20250512.1-1-x86_64.pkg.tar.zst.sig"
GPG then reads the signature file and will tell you if it matches.
For example:
$ wget https://archive.archlinux.org/packages/a/abseil-cpp/abseil-cpp-20250512.1-1-x86_64.pkg.tar.zst{,.sig}
$ gpg --verify abseil-cpp-20250512.1-1-x86_64.pkg.tar.zst.sig
gpg: assuming signed data in 'abseil-cpp-20250512.1-1-x86_64.pkg.tar.zst'
gpg: Signature made Tue 17 Jun 2025 16:30:48 UTC
gpg: using RSA key F00B96D15228013FFC9C9D0393B11DAA4C197E3D
gpg: Can't check signature: No public key
Comment too long. Click here to view the full text.