A similar idea was described in 2015: https://grimoire.ca/git/detached-sigs
Looks like a really cool approach for git-tag based release management in a CI level.
TIL about git-notes which looks pretty neat.
Is there anything out there that doesn't need GPG? Having a working GPG install is a huge lift for developers.
A similar idea was described in 2015: https://grimoire.ca/git/detached-sigs