Git was not intended (AFAIK) to be cryptographically secure. Being unsuitable for crypto != being unsuitable for other uses.
Doesn't the security of those signatures depend on the security of the SHA-1 hashes that are being signed?
[0] https://git-scm.com/book/en/v2/Git-Tools-Signing-Your-Work
By that logic, would MD5 be fine? MD4? CRC32?