It is still pretty new, and from what I understand upgrading can be a bit of a pain, but pacman 4.0 has package signing.
Been using Fedora for a bit now, so haven't actually tried it yet...