A signature binds a key holder to one commit hash, and through it to the exact tree and every parent: this change came from Sam, and history has not been altered since. That matters most where code becomes running software, such as release tags and the branch a pipeline deploys, and in projects with many contributors, where a forged author line could slip in a backdoor. A stolen key signs as well as its owner, so key management (Key Management and Revocation) is half the work.
Git 1,932 signs with an external program chosen by gpg.format:
| Method | gpg.format | Keys come from | Expiry and revocation | Best for |
|---|---|---|---|---|
| OpenPGP (GnuPG 6,212 ) | openpgp (default) | A GPG keyring | Built into keys | Long-lived identities, distro packaging |
| SSH | ssh (Git 2.34) | The key you push with | allowed_signers options, revocation file | Most developers today |
| X.509 (gpgsm) | x509 | A corporate PKI | Certificates, CRLs | Enterprises with a CA |
| Sigstore 69,885 gitsign 1,126 | x509 via gitsign | Short-lived certificates from an identity login | Certificates expire in minutes | Keyless signing in CI |
Signed Tags already signed BookNest's v1.1.0 tag with SSH. Commits are signed the same way with git commit -S, or always with commit.gpgSign true; tags with tag.gpgSign true.