Vigilant mode exists, and would have flagged the malicious commit as unverified in this case. Maybe it should be the default.
https://docs.github.com/en/authentication/managing-commit-si...
https://docs.github.com/en/authentication/managing-commit-si...
No comments yet.