It's not guaranteed not to change. The UI just makes it harder to update.
would clobber existing tag
Really wish my coworkers would leave old tags as they were heh.
I'm sure that would cause problems for some, but transitive labels already exist in Git: branches.
Of course, the repository owner has unlimited privilege here, hence the last part of my prior comment.
Packed refs are a little more complicated but all of the storage formats in git are trivial to manually edit or write a tool to handle, in extremis.
https://docs.github.com/en/repositories/configuring-branches...
https://docs.gitlab.com/user/project/protected_tags/
https://forgejo.org/docs/latest/user/protection/#protected-t...
One is refs/heads/<name> and the other is refs/tags/<name>
Branches are expected to change. When a commit is authored, HEAD (the current branch) updates to that commit.
Tags are expected not to change (though they can).