GnuPG 2.4 6,212 (preinstalled on Ubuntu 26.04 225 ; Gpg4win 108,938 on Windows, brew 6,457 install gnupg on macOS) creates an Ed25519 signing key in one command. Sam keeps BookNest on SSH signatures, so he tries GPG in a scratch repository:
gpg --batch --passphrase '' --quick-gen-key "Sam Rivera <sam@example.com>" ed25519 sign 1y
gpg --list-secret-keys --keyid-format long
git init -q ../sign-lab && cd ../sign-lab
git config set user.signingKey sam@example.com
git commit --allow-empty -qS -m "Sign a commit with GPG"
git verify-commit HEAD
cd ../booknest...
sec ed25519/70C29C786E24664C 2026-09-25 [SC] [expires: 2027-09-25]
0862AD9C4F89531A619B6BF770C29C786E24664C
uid [ultimate] Sam Rivera <sam@example.com>
gpg: Signature made Fri Sep 25 19:49:29 2026 +08
gpg: using EDDSA key 0862AD9C4F89531A619B6BF770C29C786E24664C
gpg: issuer "sam@example.com"
gpg: Good signature from "Sam Rivera <sam@example.com>" [ultimate]The key expires in one year (1y) and can only sign ([SC]: sign and certify). --batch --passphrase '' skips the passphrase prompt for this demonstration; for a real key, run gpg --quick-gen-key without them and choose a passphrase, which gpg-agent then caches. user.signingKey accepts an email address or the long key ID, and -S signs one commit. The Signature made time is when GnuPG signed, independent of the commit date.
For a host's "Verified" badge, add the output of gpg --armor --export sam@example.com to your account. "gpg failed to sign the data" usually means the agent cannot prompt for the passphrase; export GPG_TTY=$(tty) in your shell profile fixes most cases.