I’m not sure if this is legally binding, but it’s a way to prove that someone said “I signed this document and it has not been modified.” While S/MIME certificates are most commonly used for this purpose, getting one (especially for free) is nearly impossible. Signing with a GPG key is just using another tool, one whose ecosystem doesn’t require CA-sanctioned trust; the reader decides which keys are trusted and verified.
Sounds like a great excuse to fork the project and start its own community. Of course, keep integrating upstream fixes, but maybe make the logo a trans pride flag.