when you first create a package, you generate a public/private keypair specific to that app. Only a holder of the private key is allowed to push updates to the app.