The releases are tagged and signed in the PHP Git Repository. The following official GnuPG keys of the current PHP Release Manager can be used to verify the tags:
pub rsa4096 2021-04-01 [SC]
1198 C011 7593 497A 5EC5 C199 286A F1F9 8974 69DC
uid [ultimate] Pierrick Charron <pierrick@php.net>
sub rsa4096 2021-04-01 [E]
pub rsa4096 2016-11-25 [SC]
AFD8 691F DAED F03B DF6E 4605 63F1 5A9B 7153 76CA
uid [ultimate] Eric A Mann <eric@sixthree.me>
uid [ultimate] Eric A Mann <eric@eamann.com>
uid [ultimate] Eric A Mann <eric@eam.me>
uid [ultimate] Eric Mann <ericmann@php.net>
sub rsa4096 2016-11-25 [S]
sub rsa4096 2016-11-25 [E]
sub rsa4096 2016-11-25 [A]
pub ed25519 2021-04-10 [SC]
C28D937575603EB4ABB725861C0779DC5C0A9DE4
uid [ultimate] Jakub Zelenka <bukka@php.net>
uid [ultimate] Jakub Zelenka <jakub.openssl@gmail.com>
uid [ultimate] Jakub Zelenka <jakub.zelenka@gmail.com>
sub cv25519 2021-04-10 [E]
A full list of GPG keys used for current and older releases is also available.