Müzakirə

GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures

Başladan The Hacker News · 08 iyl 2026 15:08 · 16 Baxış · 0 Cavablar
Mövzunu Açan #0
New research shows that a signed Git commit's hash is not the one-of-a-kind name that much of the software world assumes it to be. Given any signed commit, someone without the signing key can mint a second commit with the same files, author, and date, and a valid signature, GitHub still stamps "Verified."

Everything a reviewer would check matches. The commit's hash does not. That matters

Okumaya devam et...

Cavab vermək üçün daxil olmalısınız.

0 sitat seçildi