In other words that means that some nostr users sort of "sign" your package and if I trust this user I trust your package. Did I get it right?
Correct
Thanks very much for that great explanation