I'm a maintainer on gitsign and think we can fix it though!
I'd like to think that when a package maintainer for a Linux distro downloads the latest version of the code they are packaging, they check that all the commits are signed by the same developer IDs as last time.
Okay, that's an over-simplification because you need to allow for key rotation, and new people joining the project, but that could be tractable or even automatable with a few heuristics and tools.
For example, there could be a tool for checking if new keys were signed by previous keys with the same email address, and there could be a contributors.policy file which specifies who the project leaders are and how many of them are needed to sign off on a given release or commit.
Did you mean to write "the most [used] form"? If so, it's unreliable. If you change your Git settings to use Torvals' email address, on GitHub it will show up as if your commits were made by his account[1].
[1]: <https://dev.to/martiliones/how-i-got-linus-torvalds-in-my-co...>
Yeah. Too late to edit.
I know that, but I postulate that people look at the author of the PR in githubs UI, not individual commits. Even if they did, the verified badge only points to a github profile anyway. So.. an attacker would much rather want to impersonate a github profile than a commit. I guess.