Security Flaw Lets Attackers Rewrite GitHub Verified Commits Without Breaking Signatures
Researchers discovered a vulnerability in Git's commit signing process that allows attackers to rewrite verified commits on GitHub without invalidating their signatures. This undermines the trust in commit verification, potentially enabling malicious code to be disguised as coming from a trusted source. The flaw highlights a critical gap in code integrity for repositories relying on verified commits for security.