Analysis of Commit Signing on Github

πŸ“… 2026-04-15
πŸ“ˆ Citations: 0
✨ Influential: 0
πŸ“„ PDF
πŸ€– AI Summary
This study addresses a critical gap in existing research, which has predominantly assessed commit signing adoption from a repository-centric perspective, thereby failing to capture developers’ actual signing behaviors and their real-world implications for software supply chain security. For the first time, we employ a platform-scale, developer-centered analytical framework, tracking 71,694 active GitHub users and their 16 million commits. By integrating large-scale behavioral logs, metadata analysis, audits of PGP/Git verification mechanisms, and key lifecycle assessments, we uncover systemic deficiencies in current signing practices: after excluding platform-generated signatures, fewer than 6% of developers have ever manually signed a commit; most manual signatures originate from the web interface; approximately 12.5% of locally signed commits are unverifiable due to missing public key uploads; and over 25% of users retain expired yet unrevoked keys.

Technology Category

Data Mining & Knowledge Management: Representing, Reasoning, and Using Provenance, TrustReasoning under Uncertainty: Other Foundations of Reasoning under UncertaintyPlanning, Routing, and Scheduling: Scheduling under Uncertainty

Application Category

Security and Privacy: Large-scale security measurementsWeb Mining and Content Analysis: Web data provenance, reliability, and authenticityResponsible Web: Social and technical mechanisms of refusal for web technologies and applications
πŸ“ Abstract
Commit signing is widely promoted as a foundation of software supply-chain security, yet prior work has studied it through the lens of individual repositories or curated project samples, missing the broader picture of how developers behave across an entire platform. Grounded in replicability theory, we vary the sampling unit from repositories to individual developers, following 71,694 active GitHub users, defined as accounts that have authored at least one commit, across all their repositories and their entire commit history, spanning 16 million commits and 874,198 repositories. This platform-wide, user-centric view reveals a fundamental gap that repository sampling cannot detect. The ecosystem's apparent high signing adoption rate is an illusion. Once platform-generated signatures are excluded, fewer than 6% of developers have ever signed a commit themselves, and the vast majority of apparent signers have never signed outside a web browser. Among the minority who do sign locally, signing rarely persists over time or across repositories, and roughly one in eight developer-managed signatures fails verification because signing keys are never uploaded to GitHub. Examining the key registry, we find that expired keys are almost never revoked and more than a quarter of users carry at least one dead key. Together, these findings reveal that commit signing as practiced today cannot serve as a dependable provenance signal at ecosystem scale, and we offer concrete recommendations for closing that gap.
Problem

Research questions and friction points this paper is trying to address.

commit signing
software supply-chain security
developer behavior
key management
provenance
Innovation

Methods, ideas, or system contributions that make the work stand out.

commit signing
developer-centric analysis
software supply-chain security
key management
GitHub
πŸ”Ž Similar Papers
πŸ’Ό Related Jobs
No related jobs found.
A
Abubakar Sadiq Shittu
University of Tennessee, Knoxville, TN, USA
J
John Sadik
University of Tennessee, Knoxville, TN, USA
F
Farzin Gholamrezae
University of Tennessee, Knoxville, TN, USA
S
Scott Ruoti
University of Tennessee, Knoxville, TN, USA