Enable signed-by option in sources.list
There is this Signed-By option that you can see in sources.list(5), if we use that we can set it in /etc/sources.list.d/leap.list which will help limit our scope (it restricts which keys can sign which repos, instead of it all being lumped together)
(from redmine: created on 2016-08-30)