You can also sign with a different key than your “regular” ssh key(s), and as such reduce the chance you’ll have to replace them.
Having said that, key rotation and distribution is obviously better with GPG, and I personally have been using that for years.
(disclosure: I'm a maintainer for gitsign)
I personaly use GPG. However, GPG looks complex and the ergonomics of GnuPG cli is horrible.
CLI ergonomic around working with ssh keys and ssh certificates is not great either.
And GPG/PGP at least has some standards around key distribution, web of trust, subkeys, etc.
SSH keys if used in place of GPG would have almost the same UI. It's not the problem of GPG, but of the underlying concepts.
You don't need to be deep into cryptography, just understand some basic concepts from the wikipedia article, or whatnot.
Therefore, making things easier to set up makes a greater contribution to security than strict, gold-standard security features that nobody adopts.