Your comments

+1 this is very useful

I'd suggest to color the icon, depending on the outcome of the GPG signature verification (like red = unverified, green = ok, yellow = unknown key, ...)

However, it may not need to be displayed in the graph (for the favor of readability), but somewhere in the commit details (probably below the author).