Security is achieved through other means.
Let's explicit this: you can, and should, sign your commits if you want security (no commit tampering). You need to:
- generated a gpg key:
gpg --full-generate-key - set git to look for the public key to use:
git config --global user.signingkey [public key ID] - set git to sign your commits:
git config --global commit.gpgsign true
Note that I used --global here but you can do without to sign on a per-project basis.
Also gpg UX is terrible, to find the [public key ID] use the command gpg --list-keys, it should looks like:
pub ed25519 2026-01-01 [SC] <- type algorithm date and capability (this key is only to Sign and Certify)
662E3CDD6FE329002D0CA5BB40339DD82B12EF16 <- Public key ID
uid [ultimate] my full name (Master Key) <my_email@domain.com> <- owner information (should be your name and email address)
sub rsa4096 2026-01-01 [E] <- sub key used to encrypt
sub ed25519 2026-01-01 [S] [expires: 2027-01-01] <- subkey used to sign
Last, if you want to save/backup you keys the default location of gpg files is ~/gnupg or you can export keys with gpg --export [key ID] > path/to/file.key for the public part and gpg --export-secret-keys [private key ID] for the private part. Both export can have a -a or --armor argument to output as base64 text instead of raw binary. [private key ID] can be found with gpg --list-secret-keys.
EDIT: after writing this I checked https://git-scm.com/book/en/v2/Git-Tools-Signing-Your-Work and TIL you can sign tags too.
EDIT 2: you can also use your ssh key to sign -> git config --global gpg.format ssh (I am less inclined to do this as you won't have subkeys and expiration date but this would be simplier indeed)