Agreed, my call was for trusted people with accounts on pelix to upload binaries. Stuff that ends up in incoming should not be copied to the distribution dir without verification. The verification can be a pgp/gpg signature or an md5sum verified OOB.