If you use Fedora Media Writer to write Silverblue to your USB stick, it automatically verifies the checksum/sig
when you install secureblue, it pulls the unverified image first to pull the pubkey and then automatically rebases you into the signed image on firstrun.