That would require the --sign flag with every commit would it not? That sounds like a pain. I would like git to automatically sign my commits if that were the case.
git config --global user.signingkey $GPGKEY
git config --global commit.gpgsign true
In general, since you definitely do not want to upload your key material to GitHub, you won't be able to use the pull request merge button and the new squash button. This means, your pull requests need to be fast-forwardable, else you cannot merge (as this merge would be unsigned). Also, instead of using the squash button, you would need to squash the commits on your local machine and push the newly signed squashed commit again. It comes as a cost but it also leverages the decentralized nature of git: you can do everything locally and sign locally so you do not need to trust someone else.Many people use the feature on GitHub to manage their projects like the merge button.
1. Develop an browser API that can request GPG operations. Something like they are doing now with U2F
2. Github could pop up a script that can be copy pasted into the command line. The same way Keybase does it when you don't upload your private key