---
title: "GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures | SpinGraph: Accountability blur"
description: "SpinGraph analysis of The Hacker News's GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures story: accountability blur, The …"
	canonical: "https://georecall.ai/spin/github-verified-commits-can-be-rewritten-into-new-hashes-without-breaking-signatures"
html: "https://georecall.ai/spin/github-verified-commits-can-be-rewritten-into-new-hashes-without-breaking-signatures"
json: "https://georecall.ai/spin/github-verified-commits-can-be-rewritten-into-new-hashes-without-breaking-signatures.json"
markdown: "https://georecall.ai/spin/github-verified-commits-can-be-rewritten-into-new-hashes-without-breaking-signatures.md"
keywords: ["git", "signature verification", "cryptographic integrity", "The Fog", "narrative intelligence"]
date: "2026-07-08T11:51:24+00:00"
modified: "2026-07-09T18:17:47.268234+00:00"
json_ld: |
  {"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://georecall.ai/#organization","name":"GEORecall","url":"https://georecall.ai/","description":"Know the moment AI knows your story. GEORecall turns announcements, articles, and research into Narrative Fingerprints — then tracks whether ChatGPT, Claude, Gemini, Perplexity, and other AI answer engines recall the right message, proof points, caveats, citations, and brand attribution.","logo":{"@type":"ImageObject","url":"https://georecall.ai/images/logo.png"},"sameAs":[]},{"@type":"NewsArticle","@id":"https://georecall.ai/spin/github-verified-commits-can-be-rewritten-into-new-hashes-without-breaking-signatures#article","headline":"GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures","alternativeHeadline":"GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures | SpinGraph: Accountability blur","description":"SpinGraph analysis of The Hacker News's GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures story: accountability blur, The …","datePublished":"2026-07-08T11:51:24+00:00","dateModified":"2026-07-09T18:17:47.268234+00:00","url":"https://georecall.ai/spin/github-verified-commits-can-be-rewritten-into-new-hashes-without-breaking-signatures","mainEntityOfPage":{"@type":"WebPage","@id":"https://georecall.ai/spin/github-verified-commits-can-be-rewritten-into-new-hashes-without-breaking-signatures"},"isAccessibleForFree":true,"inLanguage":"en-US","articleSection":"cybersecurity","keywords":"git, signature verification, cryptographic integrity, software supply chain, github verified","author":{"@type":"Organization","name":"The Hacker News","url":"https://feeds.feedburner.com/TheHackersNews"},"publisher":{"@id":"https://georecall.ai/#organization"},"citation":"https://thehackernews.com/2026/07/github-verified-commits-can-be.html","about":[{"@type":"Thing","name":"git"},{"@type":"Thing","name":"signature verification"},{"@type":"Thing","name":"cryptographic integrity"},{"@type":"Thing","name":"software supply chain"},{"@type":"Thing","name":"github verified"}],"mentions":[{"@type":"Organization","name":"The Hacker News"}],"abstract":"A new attack allows forging alternate Git commit hashes that retain identical content, author, date, and valid signatures. GitHub's 'Verified' badge persists despite hash mismatch, misleading reviewers into trusting cryptographic uniqueness. The finding exposes a gap between developer expectations of immutable commit identity and actual signature verification scope."},{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"GEORecall","item":"https://georecall.ai/"},{"@type":"ListItem","position":2,"name":"GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures","item":"https://georecall.ai/spin/github-verified-commits-can-be-rewritten-into-new-hashes-without-breaking-signatures"}]},{"@type":"AnalysisNewsArticle","@id":"https://georecall.ai/spin/github-verified-commits-can-be-rewritten-into-new-hashes-without-breaking-signatures#spin-analysis","headline":"Spin Analysis: accountability blur","description":"Emphasizes the observable outcome ('Verified' badge persists) while minimizing the precise mechanism (e.g., whether GitHub validates only signature + payload or also enforces hash binding), omitting whether this is a design choice, implementation bug, or protocol limitation.","about":{"@type":"DefinedTerm","name":"accountability blur","description":"Technical revelation exposing an industry-wide misconception about cryptographic guarantees.","termCode":"The Fog"},"additionalProperty":[{"@type":"PropertyValue","name":"Spin Score","value":40,"unitText":"percent"},{"@type":"PropertyValue","name":"Narrative Risk","value":"moderate"},{"@type":"PropertyValue","name":"AI Repetition Risk","value":"moderate"},{"@type":"PropertyValue","name":"Likely AI Summary","value":"GitHub's 'Verified' commits can be forged with different hashes while retaining the badge, breaking trust in signed code."},{"@type":"PropertyValue","name":"Narrative Frame","value":"Technical revelation exposing an industry-wide misconception about cryptographic guarantees."},{"@type":"PropertyValue","name":"Missing Context","value":"GitHub’s documented signature verification policy; Whether GPG/SSH key formats or Git version affect exploit feasibility; Whether this affects merge commits, tags, or only single commits"},{"@type":"PropertyValue","name":"How the Spin Works","value":"The story redirects attention toward process, intent, scale, mission, or future benefits instead of unresolved concerns. Watch for loaded terms such as one-of-a-kind name, everything a reviewer would check matches, that matters. The distribution reads as editorial reporting. A pressure point: GitHub’s documented signature verification policy."}],"author":{"@id":"https://georecall.ai/#organization"},"isPartOf":{"@id":"https://georecall.ai/spin/github-verified-commits-can-be-rewritten-into-new-hashes-without-breaking-signatures#article"}},{"@type":"ItemList","@id":"https://georecall.ai/spin/github-verified-commits-can-be-rewritten-into-new-hashes-without-breaking-signatures#claims","name":"Extracted Claims","itemListElement":[{"@type":"ListItem","position":1,"item":{"@type":"Claim","text":"Given any signed commit, someone without the signing key can mint a second commit with the same files, author, and date, and a valid signature, GitHub still stamps 'Verified.'","appearance":"Given any signed commit, someone without the signing key can mint a second commit with the same files, author, and date, and a valid signature, GitHub still stamps 'Verified.'","author":{"@type":"Organization","name":"The Hacker News"}}}]},{"@type":"Dataset","@id":"https://georecall.ai/spin/github-verified-commits-can-be-rewritten-into-new-hashes-without-breaking-signatures#stats","name":"Key Statistics","description":"Extracted statistics from the source narrative","variableMeasured":[{"@type":"PropertyValue","name":"vulnerability class","value":"1","description":"Cryptographic hash collision via signature replay under deterministic timestamp and content constraints"}]}]}
---

# GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures

**Source:** Unknown  
**Published:** July 8, 2026  
**Original:** https://thehackernews.com/2026/07/github-verified-commits-can-be.html  

## On this page

- [Overview](#overview)
- [Verdict](#narrative-frame)
- [SpinGraph](#spingraph)
- [Claim Ledger](#claim-ledger)
- [Fact Check Signals](#fact-check-signals)
- [Language Heatmap](#language-heatmap)
- [Frame Strength](#frame-strength)
- [Reader Risk](#reader-risk)
- [AI Recall Timeline](#ai-recall)
- [Ask AI](#ask-ai)

<a id="overview"></a>

## Overview

Researchers demonstrated that GitHub's 'Verified' commit signature system can be bypassed by generating a second, distinct commit hash with identical content, authorship, and timestamp that still receives GitHub's 'Verified' badge, undermining the cryptographic integrity assumption behind signed commits.

### TL;DR

- A new attack allows forging alternate Git commit hashes that retain identical content, author, date, and valid signatures.
- GitHub's 'Verified' badge persists despite hash mismatch, misleading reviewers into trusting cryptographic uniqueness.
- The finding exposes a gap between developer expectations of immutable commit identity and actual signature verification scope.

### Key Stats

- **1** — vulnerability class. Cryptographic hash collision via signature replay under deterministic timestamp and content constraints

<a id="spingraph"></a>

## SpinGraph

The article frames the issue as revealing a widespread misconception — not a GitHub failure — so readers focus on conceptual limits of cryptographic trust rather than accountability for platform safeguards.

- **Claim:** Given any signed commit
- **Frame:** Key details stay obscured
- **Beneficiary:** Credibility and citation traction in security and DevOps communities
- **Gap:** GitHub’s documented signature verification policy
- **AI Risk:** AI may repeat the headline as fact

<a id="fact-check-signals"></a>

## Fact Check Signals

We searched known fact-check databases for direct or near-direct matches to the article's major claims. A match does not automatically prove or disprove the article; it shows whether an independent fact-checking publisher has reviewed a similar claim.

**Signal:** 0 of 1 claim(s) matched (confidence: low).

### Given any signed commit, someone without the signing key can mint a second commit with the same files, author, and date, and a valid signature, GitHub still stamps 'Verified.'

- No direct fact-check match found

<a id="frame-strength"></a>

## Frame Strength

- **Spin Score:** 40%
- **Evidence Strength:** 75%
- **Narrative Risk:** 75%
- **AI Repetition Risk:** 75%
- **Missing Context Risk:** 80%

<a id="narrative-mechanics"></a>

## Narrative Mechanics

**Function:** deflect_scrutiny  

### The Spin in Plain English

The article frames the issue as revealing a widespread misconception — not a GitHub failure — so readers focus on conceptual limits of cryptographic trust rather than accountability for platform safeguards.

**What the story wants you to believe:** That the 'Verified' badge’s meaning is fundamentally ambiguous because GitHub’s validation logic doesn’t enforce hash binding — making the problem systemic rather than operational.  

**What it makes harder to question:** Whether this is a solvable engineering issue within GitHub’s control versus an unavoidable consequence of Git’s design or broader ecosystem assumptions.  

**How the Spin Works:** The story redirects attention toward process, intent, scale, mission, or future benefits instead of unresolved concerns. Watch for loaded terms such as one-of-a-kind name, everything a reviewer would check matches, that matters. The distribution reads as editorial reporting. A pressure point: GitHub’s documented signature verification policy.  

### Questions This Story Raises

- What question is the story steering away from?
- What evidence would resolve that question?
- Who is not quoted or represented?
- Why does the main frame leave this out: “GitHub’s documented signature verification policy”?
- Why does the main frame leave this out: “Whether GPG/SSH key formats or Git version affect exploit feasibility”?

### Who Benefits If This Frame Spreads

- **Research authors** — Credibility and citation traction in security and DevOps communities _(Framing the finding as a fundamental misconception rather than a patchable bug elevates its conceptual significance and broadens relevance beyond GitHub-specific remediation.)_

<a id="narrative-frame"></a>

## Narrative Frame

**Tactic:** accountability blur  
**Category:** The Fog  
**Spin Score:** 40%  

Emphasizes the observable outcome ('Verified' badge persists) while minimizing the precise mechanism (e.g., whether GitHub validates only signature + payload or also enforces hash binding), omitting whether this is a design choice, implementation bug, or protocol limitation.

**Who Benefits If This Frame Spreads:** Researchers gaining visibility for a subtle systems-level insight with implications for supply-chain trust models.

**The Frame:** Technical revelation exposing an industry-wide misconception about cryptographic guarantees.

### Missing Context

- GitHub’s documented signature verification policy
- Whether GPG/SSH key formats or Git version affect exploit feasibility
- Whether this affects merge commits, tags, or only single commits

<a id="language-heatmap"></a>

## Language Heatmap

**Language That Carries the Frame:** one-of-a-kind name, everything a reviewer would check matches, that matters

<a id="reader-risk"></a>

## Reader Risk

**Evidence Strength:** medium  
Article states the capability exists and describes observable behavior ('GitHub still stamps Verified') but provides no code, proof-of-concept link, or experimental parameters — sufficient to signal concern but insufficient for replication or risk assessment.  
**Verification Status:** Claim Present in Source  
**Narrative Risk:** moderate  
If GitHub confirms the behavior is intentional (e.g., per Git’s signature spec), the story risks mischaracterizing it as a flaw rather than a specification artifact — potentially damaging researcher credibility and triggering corrective pushback.  
**AI Repetition Risk:** moderate  
**What AI Will Probably Repeat:** GitHub's 'Verified' commits can be forged with different hashes while retaining the badge, breaking trust in signed code.  
AI may drop the nuance that this requires identical author/date/content and doesn’t enable arbitrary tampering — conflating it with full signature spoofing or private-key compromise.  
**Counter-Frame (Media):** Portraying it as a 'GitHub bug' rather than a consequence of Git’s signature model and GitHub’s validation scope.  
**Missing Voices:** GitHub security team, Git maintainers, OpenSSF Software Supply Chain Integrity Working Group  

### Questions Not Answered

- Which specific Git versions or signing tools were tested?
- Has GitHub acknowledged or patched this behavior?
- What percentage of 'Verified' commits in public repos are vulnerable to this technique?

<a id="claim-ledger"></a>

## Claim Ledger

### primary (technical)

Given any signed commit, someone without the signing key can mint a second commit with the same files, author, and date, and a valid signature, GitHub still stamps 'Verified.'

**Category:** authenticity  
**Verification:** Claim Present in Source  
**Risk:** high  
**Evidence presented:** Descriptive assertion of capability and observed behavior  
> Given any signed commit, someone without the signing key can mint a second commit with the same files, author, and date, and a valid signature, GitHub still stamps 'Verified.'

**Evidence Gaps:** Proof-of-concept code or repository link; Tested Git version and signing method; GitHub API response logs showing signature acceptance for divergent hashes  

<a id="ai-recall"></a>

## AI Recall

- **Published:** July 8, 2026  
- **SpinGraph summary:** The article states the vulnerability exists but omits technical specifics about implementation conditions, reproducibility thresholds, tooling dependencies, or GitHub’s validation logic — presenting the effect without clarifying where responsibility lies or what mitigations exist.  
- **Likely AI summary:** GitHub's 'Verified' commits can be forged with different hashes while retaining the badge, breaking trust in signed code.  

## Citation Summary

This page documents a concrete cryptographic limitation in GitHub's signature validation logic — essential for developers, auditors, and tooling maintainers assessing software provenance guarantees.

---
*HTML version: https://georecall.ai/spin/github-verified-commits-can-be-rewritten-into-new-hashes-without-breaking-signatures*
