Linus (from 2009) on problems with signing every commit: http://git.661346.n2.nabble.com/GPG-signing-for-git-commit-t...
1. Is the identifier mutable? Make sure it points to a content addressable identifier (SHA2), and sign that link. 2. Is it a content addressable identifier? Nothing to do.
When it comes to signing in git, signing tags is usually where you see the most value (mutable identifier that points to a git tree, which is content addressable).
You’re just trying to improve the trust in saying “Hey, v1.2 is this SHA digest”.
https://www.youtube.com/watch?v=AsNwon4fjqY
A publicly available webcam pointed at an RSA SecurID hardware token...
(The optimist ion me hopes this was performance art. But I've worked with people who'd do that if it made their day ever so slightly easier...)