The openpgpkey-control repo can emit a bundle of keys, such as we
distribute for the maintainer keyring. That bundle is "keys, plus
signatures from other keys in the bundle". In addition, it will not
export each key in the bundle, with those other sigs on it.
So one `update-bundles` command later, we have a version of Heiko's key
with signatures from other people on it.
And Jeremy's key now has an @exim.org UID upon it.