GitHub commit Verification logic flaw and bypass
GitHub's commit "Verified" badge checks only the committer's key, not the author field, which can be spoofed via Git env vars. Attackers can show a verified badge next to any forged identity. The defense (Vigilant Mode) is opt-in and off by default.