CYBER● ELEVATEDJul 8 · Jul 8, 2026, 11:51 AM
GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures
The Hacker News
New research shows that a signed Git commit's hash is not the one-of-a-kind name that much of the software world assumes it to be. Given any signed commit, someone without the signing key can mint a second commit with the same files, author, and date, and a valid signature, GitHub still stamps "Verified." Everything a reviewer would check matches. The commit's hash does not. That matters
GlobeAlert aggregates and classifies open sources; the story above belongs to its publisher. Summaries are machine-generated from the source text.
More in Cyber
CYBERnow[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AIDark ReadingCYBERnow[Virtual Event] Building a Secure AI Strategy for the EnterpriseDark ReadingCYBER1h agoMeet the CISO: A new front line star in the AI cybersecurity warCNBCCYBER4h agoOpenAI AI agents hack German site in undisclosed incident , use it to coordinate and bypass restrictionsdigit.in · India