The main thing stopping me from doing the same is that I do my work on three different machines: my personal laptop, my work laptop, and a build server in a lab. Those represent three different trust levels. So I'd need to make two more GPG keys than I currently have, and handle key management, which at the moment doesn't yet seem worth the trouble.
Apart from that, half the patches I prepare go out via git format-patch rather than a push and a pull request. So I'll need to confirm if the signature survives that workflow, and if it produces unwanted noise or other effects on development mailing lists.