The new code might retain ability to decrypt the old version but not encrypt with the old version, for compatibility with old backup files or whatever. If he thinks it's safe to do.
You also state that tool may or may not be able interact with past files. Which means it might be useless.
Git is in the process of deprecating sha1, and you end up having the put flexibility in after a tool expands. It will likely keep supporting sha1 even after it is much more trivial to create collisions.
I trust his judgement much more than I trust the group that maintains gpg. Of course, actually, there is a community, Filippo is not working in a vacuum. Worst case, if Filippo stops maintaining it or makes bad decisions, someone else (or a group of people) will maintain it.
[1] https://github.com/cr-marcstevens/sha1collisiondetection
Getting minisign to sign using a key in a ubikey is not supported out of the box, but should be possible in the same way yubikey-agent works (after all, that's what it does when you authenticate an ssh session using a yubikey).
You can ask Filippo Valsorda.
https://github.com/FiloSottile/age#ssh-keys
> (ssh-agent is not supported.)
There is no way it integrates with smartcards.