It's true that different open source projects care about different things (and some may genuinely not care about who contributes), but there are plenty of prominent open source software projects (the linux kernel, various programming languages, apache, etc) who deal with people who would like to submit vulnerabilities or simply cannot code well enough to avoid problems. It seems like all projects would like to avoid those outcomes, even if their legal situation is different, and providing a verifiable certificate chain could be a method of achieving that (either in contributions or in distribution).