As per gradle/gradle#33940, Gradle now signs distro artifacts using PGP. More information availble on dedicated docs.
Eventually there is room to leverage rpgp and validate also the signatures of any existing wrapper. We can validate also the signatures of the Gradle distribution zipball.