Always sign your commits!
Always sign your commits!
We do NOT know this.
> We do NOT know this.
Well, at least we know that the attackers wanted their activities to be noticed at this point in time.
I have reasons to suspect that this is a compromised account, in which case there should be enough forensics info to figure out what the scope of the damage is.
Likewise, I wonder if git differentiates signatures where the keys are set as trusted in gnupg, and those that are not.
They do this
Sure, if GitHub wanted to completely abandon the decentralized nature of Git and be a completely centralized system. Which it would love to, I'm sure, but I don't think the user base is quite ready for them to completely shut off any repository with any commits not made by Github users, and posted to GitHub through the account of the user who made the commit, which is what you are suggesting.
How on earth do you know they haven't done both?!
Thus maintainers usually sign merge commits and it's their job to confirm that commits don't do anything shady and come from people they claim to come from.
Unfortunately PGP is fundamentally broken. Any identity (email address) can be trivially DoS'd by anyone, because the keyservers are (by design) write-only databases which anyone can add to.
https://gist.github.com/rjhansen/67ab921ffb4084c865b3618d695...
I don't need a key server for me to sign or validate that something was signed by who it said it was if exchanged my keys via a secure means.
It has no effect on GitHub, though, which doesn’t use keyservers as part of its validation process.