FeedGitHub 'Verified' Commits Can Be Rewritten Into New Hashes W...
The Hacker News

GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures

📅 8 July 2026 at 11:51 UTC📰 The Hacker NewsView original source ↗
GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures

New research shows that a signed Git commit's hash is not the one-of-a-kind name that much of the software world assumes it to be. Given any signed commit, someone without the signing key can mint a second commit with the same files, author, and date, and a valid signature, GitHub still stamps "Verified." Everything a reviewer would check matches. The commit's hash does not. That matters

Read the full article

This is a curated summary. The complete article is available at The Hacker News.

Read on The Hacker News
← Back to feed