I imagine in the future you could have signature validation for code signing purposes tied to Nostr identities. So rather than utilizing third-party key servers, you could go straight to the user's Nostr profile for verification.
Though I suppose that would require signing code with the same private key used for Nostr.
**thinking out loud**