Download the signature-database shards into the cache directory and return where they landed. Prefers the
committed sigdb.remote.json, we verify each download by content hash, and skip shards already
present with the right hash.
Use the returned SigDbDownloadResult.manifest, or point solver.sigdb.additionalPaths at the dir.
Download the signature-database shards into the cache directory and return where they landed. Prefers the committed
sigdb.remote.json, we verify each download by content hash, and skip shards already present with the right hash. Use the returned SigDbDownloadResult.manifest, or pointsolver.sigdb.additionalPathsat the dir.