Why Sign Commits and Tags

A signature binds a key holder to one commit hash, and through it to the exact tree and every parent: this change came from Sam, and history has not been altered since. That matters most where code becomes running software, such as release tags and the branch a pipeline deploys, and in projects with many contributors, where a forged author line could slip in a backdoor. A stolen key signs as well as its owner, so key management (Key Management and Revocation) is half the work.

Git 1,932 signs with an external program chosen by gpg.format:

Ways to sign Git commits and tags
Method gpg.format Keys come from Expiry and revocation Best for
OpenPGP (GnuPG 6,212 ) openpgp (default) A GPG keyring Built into keys Long-lived identities, distro packaging
SSH ssh (Git 2.34) The key you push with allowed_signers options, revocation file Most developers today
X.509 (gpgsm) x509 A corporate PKI Certificates, CRLs Enterprises with a CA
Sigstore 69,885 gitsign 1,126 x509 via gitsign Short-lived certificates from an identity login Certificates expire in minutes Keyless signing in CI

Signed Tags already signed BookNest's v1.1.0 tag with SSH. Commits are signed the same way with git commit -S, or always with commit.gpgSign true; tags with tag.gpgSign true.