I can prove that code was signed by a key that was verified to belong to a single human body by lots of in-person high reputation humans.
How the code was authored, who cares, but I can prove it had multiple explicit cryptographic human signoffs before merge, and that is what matters in terms of quality control and supply chain attack resistance.