Really? Most two-bit cat selfie startups are at least aware enough to notice a phantom commit from Bob, but Juniper isn't?!
https://git-scm.com/book/en/v2/Git-Tools-Signing-Your-Work
does this resolve the issue for git? or is it still possible to subvert?
http://mikegerwitz.com/papers/git-horror-story https://developer.atlassian.com/blog/2015/05/git-horror-stor...
I'm not sure git is the best example of a secure system. Commercial source control systems have more serious authentication.
What used to be the central p4 server was renamed Helix, turned into a federated architecture, and there's some sort of data exfiltration protection option that is based on Interset's behavioral analytics stuff.
As far as I can tell from the marketing materials, the idea seems to be that if if a coder starts regularly looking at the sales numbers, file a report. Maybe someone needs a reminder about the consequences of insider trading, but maybe they just want to know if the project's getting traction in the real world, and the false alarm can be resolved with a brief chat. If someone tries to clone an entire corporate monorepo on a salesperson's workstation at 3 in the morning local time, shut it down, because the most likely explanation is that the salesperson's workstation has been compromised.
http://www.dwheeler.com/essays/scm-security.html
After all that, only one OSS project responded with claims to meet many of the requirements. I figure the commercial situation isn't much better with most "benefits" existing on paper rather than with strong security.
To top it off, anyone defending against nation-states must remember they always attack what's below and around the software. Possessing 0-days in OS or management software should let them bypass build-system security to insert stuff in. I'd say OpenBSD, memory-safe implementation, and highly-assured guard for protocol-level at a minimum if better stuff wasn't available.