GitHub
Security & compliance
Code quality
Commit signing not required
Part of the Repository protection posture check · fix arrives as a guide
What it is
The repository does not require commits to be signed and verified.
Why it matters
Commit author metadata is self-reported and trivially forged, so history alone does not establish who wrote what. Without signing there is no cryptographic answer to that question during an incident.
How to fix it
Enable required signed commits in branch protection once contributors have signing keys set up. Rolling it out on the default branch first keeps the disruption manageable.
Run them all on your app
Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.