We use a little tool called gt
to pull files from a git repository. I think this could help with this. It includes GPG signature verification and can syncing can be automated with GitHub workflows. It's available and documented at GitHub: https://github.com/tegonal/gt