git verify-commit and git verify-tag check one object and exit non-zero on failure, which suits scripts. For history, the %G? placeholder prints one letter per commit:
git verify-commit HEAD
git log --format="%h %G? %s" -4
git verify-tag v1.1.0Good "git" signature for sam@example.com with ED25519 key SHA256:dDyqIq8IYgZL9UIYXW/9qlZz91N3CZexZFO+SUfkdPM 8862809 G Trust Sam's SSH signing key 69a974b N Store the cover images in Git LFS 4f06d9b N Lint staged JavaScript with ESLint before each commit f8b394b N Share the pre-commit and commit-msg hooks Good "git" signature for sam@example.com with ED25519 key SHA256:dDyqIq8IYgZL9UIYXW/9qlZz91N3CZexZFO+SUfkdPM
G is a good signature from a trusted key and N no signature: BookNest's earlier commits stay unsigned, since signing them would rewrite published history. The other letters are B bad (the content changed), U good but from an unknown key, X a good signature that has expired, Y one made by an expired key, R one made by a revoked key, and E cannot be checked (for example, a missing program). "git" in the output is the SSH namespace, which stops a signature made for Git 1,932 from being reused as, say, a signed file. git log --show-signature shows each check in full, and git merge --verify-signatures refuses a branch whose tip is not signed by a trusted key.