Wrong ISO checksums on download page?

I’ve verified also the CHECKSUM signature with

aarch64$ gpg2 --verify CHECKSUM.sig CHECKSUM
gpg: Signature made Mon 21 Jun 2021 12:47:55 AM CEST
gpg:                using EDDSA key BFC3D8F20D15F4FD46281D7FAA650F52D6C094FA
gpg:                issuer "infrastructure@rockylinux.org"
gpg: Good signature from "Core Infrastructure <infrastructure@rockylinux.org>" [unknown]
gpg: WARNING: This key is not certified with a trusted signature!
gpg:          There is no indication that the signature belongs to the owner.
Primary key fingerprint: BFC3 D8F2 0D15 F4FD 4628  1D7F AA65 0F52 D6C0 94FA
x86_64$ gpg2 --verify CHECKSUM.sig CHECKSUM
gpg: Signature made Mon 21 Jun 2021 12:48:06 AM CEST
gpg:                using EDDSA key BFC3D8F20D15F4FD46281D7FAA650F52D6C094FA
gpg:                issuer "infrastructure@rockylinux.org"
gpg: Good signature from "Core Infrastructure <infrastructure@rockylinux.org>" [unknown]
gpg: WARNING: This key is not certified with a trusted signature!
gpg:          There is no indication that the signature belongs to the owner.
Primary key fingerprint: BFC3 D8F2 0D15 F4FD 4628  1D7F AA65 0F52 D6C0 94FA

haven’t seen any issues with the imported Rocky Linux public key.