Got it, thank you. I'd love it if we could make sure it works both ways--locally and on github--so we're not locked into the way github does this. I suggest improving the script so it can handle both kinds of signatures. I mean, assuming this is possible. If not, let's use the method that for sure works both locally and on github (signing commits with pgp/gpg only)--as (I think) gpg signatures are used throughout the ASF.
If we need public keys to make it work locally, we could use the github API endpoints for fetching user public SSH and GPG/PGP keys, then [cache and] use them locally. As for when to run the check, do you mean it would run before a reviewer approves workflows to run? That sounds great to me.
