> We can round up the bits that make up a commit in a SHA-1-based repo, and sign those bits securely; this is a thing that is possible.
Yes but as my other comment explains, this is not particularly useful in and of itself.
It represents an increment in security which doesn't require switching to a SHA-256 repo.
It represents an increment in security which doesn't require switching to a SHA-256 repo.