URL has been copied successfully!
GitHub ‘Verified’ Commits Can Be Rewritten Into New Hashes Without Breaking Signatures
URL has been copied successfully!

Collecting Cyber-News from over 60 sources

GitHub ‘Verified’ Commits Can Be Rewritten Into New Hashes Without Breaking Signatures

New research shows that a signed Git commit’s hash is not the one-of-a-kind name that much of the software world assumes it to be. Given any signed commit, someone without the signing key can mint a second commit with the same files, author, and date, and a valid signature, GitHub still stamps “Verified.”Everything a reviewer would check matches. The commit’s hash does not. That matters

First seen on thehackernews.com

Jump to article: thehackernews.com/2026/07/github-verified-commits-can-be.html

Loading

Share via Email
Share on Facebook
Tweet on X (Twitter)
Share on Whatsapp
Share on LinkedIn
Share on Xing
Copy link