The wax seal of software. It proves the program comes from who it claims to, and that nobody touched it on the way.
Old letters were closed with wax and the sender's crest. Anyone could read the letter, but a broken seal gave away that somebody had been inside. Code signing is the same idea, built so that the seal cannot be forged.
Which makes the private key the most valuable thing in a software project. Steal it and the thief can sign malicious code that your machine will accept as genuine. The update meant to protect you turns into the door.
Hence the iron rule: a key that has been somewhere it should not have been counts as burned. It gets revoked and replaced even when there is no trace of anyone taking it. Probabilities are not up for discussion here.
Where you meet it
Every time your phone refuses to install an app from outside the store. Every time a Linux machine complains that a repository has an unverified signature. And every time the operating system asks whether you are sure about a program from an unknown publisher. That is not a formality. It is a check.