GPG keys and Repos

is there or can we have repos and GPG key for RPM packages? would be so much better than just ignore all security notifications since there is RPM already just for adding repo and GPG key to verify package is real not tempered