You don't have to reuse your keys. You can have a separate key(s) for signing.
I personaly use GPG. However, GPG looks complex and the ergonomics of GnuPG cli is horrible.
CLI ergonomic around working with ssh keys and ssh certificates is not great either.
And GPG/PGP at least has some standards around key distribution, web of trust, subkeys, etc.
SSH keys if used in place of GPG would have almost the same UI. It's not the problem of GPG, but of the underlying concepts.
You don't need to be deep into cryptography, just understand some basic concepts from the wikipedia article, or whatnot.
Therefore, making things easier to set up makes a greater contribution to security than strict, gold-standard security features that nobody adopts.