You can use the signature file to verify that the corresponding file (without the .sig suffix) is intact. First, be sure to download both the .sig file and the corresponding tarball. Then, run a command like this:

  gpg --verify dico-2.4.tar.gz.sig

If that command fails because you don't have the required public key, then run this command to import it:

  gpg --keyserver --recv-keys 3602B07F55D0C732

and rerun the `gpg --verify' command.

You can keep track of the news and updates at the project's homepage.