I promise we are actively working on a much better solution we hope any distro can use, but... for now we just enforce signed merge commits by a different maintainer other than the author as something they only do for code they personally reviewed.
Are you looking at crev at all?
https://github.com/crev-dev/
Are you looking at crev at all?
https://github.com/crev-dev/