What alternative to GnuPG has a compatible interface (for use by Git) and does not leave behind an active lock (like pubring.db.lock) when something crashes?
You can sign git commits using SSH keys, including the one you use to connect to GitHub/GitLab/Codeberg. These sites also support verifying the signature.
At the very least you should proactively point out that you're recommending closed source, proprietary and paid software on a FOSS community, in the future.
Especially with password managers the SAAS closed source part is extremely relevant. I'd never entrust mine to that, let alone recommend it to others. Linux version with integrated ssh agent be damned.