A script should be made to have Tails signing key automatically downloaded per global Makefile and throw error if git is unclean because of that change.
The idea is to have this script manual first for local build and have guidance into developers to create an issue and PR if that key changed.
Tails change its iso signing key often which is a bit problematic, historically catched way too late.