GitHub Security & compliance Code quality

Commit signing not required

Part of the Repository protection posture check · fix arrives as a guide

What it is

The repository does not require commits to be signed and verified.

Why it matters

Commit author metadata is self-reported and trivially forged, so history alone does not establish who wrote what. Without signing there is no cryptographic answer to that question during an incident.

How to fix it

Enable required signed commits in branch protection once contributors have signing keys set up. Rolling it out on the default branch first keeps the disruption manageable.

Run them all on your app

Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.