accept also pkgfile in addition to pkgname. make also the signature verification stuff work properly again with non-repository files.