How does GPG-signing help, when the signature is over a SHA-1 hash?
Edit: Actually, looking at the code (do_sign_commit), git appears to gpg sign the whole commit object.
I think it's in signed tags where git only signs the sha1 being tagged.
So you're correct that GPG-signing commits (but not tags) prevents collisions in commit objects. The problem though is that a commit ultimately contains a SHA-1 hash of a tree object, so now the concern is someone generating colliding tree objects.
Edit: fortunately, the format of tree objects looks pretty rigid. I feel somewhat reassured, but only somewhat.
Edit: this is only true of tag signing - with commit signing you GPG-sign the whole commit object.