It might be time to consider git 2.34 or above where you can use SSH keys to sign git commits and tags. This has been around since late 2021. Git uses ssh-keygen -Y to sign and verify contents. My team is moving in that direction now that we are all on 2.35.1. We previously used GPG for this purpose.

