On the Prevalence and Usage of Commit Signing on GitHub: A Longitudinal and Cross-Domain Study
Fuente:
arXiv
Saved in:
| Main Authors: | Sharma, Anupam, Karmakar, Sreyashi, Kancherla, Gayatri Priyadarsini, Bichhawat, Abhishek |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
Exploring User Privacy Awareness on GitHub: An Empirical Study
by: Alfieri, Costanza, et al.
Published: (2024)
by: Alfieri, Costanza, et al.
Published: (2024)
Least Privilege Access for Persistent Storage Mechanisms in Web Browsers
by: Kancherla, Gayatri Priyadarsini, et al.
Published: (2024)
by: Kancherla, Gayatri Priyadarsini, et al.
Published: (2024)
Unpacking Security Scanners for GitHub Actions Workflows
by: Fares, Madjda, et al.
Published: (2026)
by: Fares, Madjda, et al.
Published: (2026)
On the effectiveness of Large Language Models for GitHub Workflows
by: Zhang, Xinyu, et al.
Published: (2024)
by: Zhang, Xinyu, et al.
Published: (2024)
Security Weaknesses of Copilot-Generated Code in GitHub Projects: An Empirical Study
by: Fu, Yujia, et al.
Published: (2023)
by: Fu, Yujia, et al.
Published: (2023)
Is GitHub's Copilot as Bad as Humans at Introducing Vulnerabilities in Code?
by: Asare, Owura, et al.
Published: (2022)
by: Asare, Owura, et al.
Published: (2022)
Characterizing and Modeling the GitHub Security Advisories Review Pipeline
by: Segal, Claudio, et al.
Published: (2026)
by: Segal, Claudio, et al.
Published: (2026)
Security in the Age of AI Teammates: An Empirical Study of Agentic Pull Requests on GitHub
by: Siddiq, Mohammed Latif, et al.
Published: (2026)
by: Siddiq, Mohammed Latif, et al.
Published: (2026)
Can Highlighting Help GitHub Maintainers Track Security Fixes?
by: Liu, Xueqing, et al.
Published: (2024)
by: Liu, Xueqing, et al.
Published: (2024)
Unveiling A Hidden Risk: Exposing Educational but Malicious Repositories in GitHub
by: Masud, Md Rayhanul, et al.
Published: (2024)
by: Masud, Md Rayhanul, et al.
Published: (2024)
LLM-Enabled Open-Source Systems in the Wild: An Empirical Study of Vulnerabilities in GitHub Security Advisories
by: Shifat, Fariha Tanjim, et al.
Published: (2026)
by: Shifat, Fariha Tanjim, et al.
Published: (2026)
Heimdallr: Characterizing and Detecting LLM-Induced Security Risks in GitHub CI Workflows
by: Ruan, Bonan, et al.
Published: (2026)
by: Ruan, Bonan, et al.
Published: (2026)
IssueGuard: Real-Time Secret Leak Prevention Tool for GitHub Issue Reports
by: Rahman, Md Nafiu, et al.
Published: (2026)
by: Rahman, Md Nafiu, et al.
Published: (2026)
Measuring Compliance of Consent Revocation on the Web
by: Kancherla, Gayatri Priyadarsini, et al.
Published: (2024)
by: Kancherla, Gayatri Priyadarsini, et al.
Published: (2024)
Six Million (Suspected) Fake Stars in GitHub: A Growing Spiral of Popularity Contests, Spams, and Malware
by: He, Hao, et al.
Published: (2024)
by: He, Hao, et al.
Published: (2024)
Bugdar: AI-Augmented Secure Code Review for GitHub Pull Requests
by: Naulty, John, et al.
Published: (2025)
by: Naulty, John, et al.
Published: (2025)
Security Concerns in Generative AI Coding Assistants: Insights from Online Discussions on GitHub Copilot
by: Ferreyra, Nicolás E. Díaz, et al.
Published: (2026)
by: Ferreyra, Nicolás E. Díaz, et al.
Published: (2026)
Analysis of Commit Signing on Github
by: Shittu, Abubakar Sadiq, et al.
Published: (2026)
by: Shittu, Abubakar Sadiq, et al.
Published: (2026)
A Longitudinal Study of Usability in Identity-Based Software Signing
by: Kalu, Kelechi G., et al.
Published: (2026)
by: Kalu, Kelechi G., et al.
Published: (2026)
Automating the Detection of Code Vulnerabilities by Analyzing GitHub Issues
by: Cipollone, Daniele, et al.
Published: (2025)
by: Cipollone, Daniele, et al.
Published: (2025)
CrossCommitVuln-Bench: A Dataset of Multi-Commit Python Vulnerabilities Invisible to Per-Commit Static Analysis
by: Majumdar, Arunabh
Published: (2026)
by: Majumdar, Arunabh
Published: (2026)
PatchSeeker: Mapping NVD Records to their Vulnerability-fixing Commits with LLM Generated Commits and Embeddings
by: Nguyen, Huu Hung, et al.
Published: (2025)
by: Nguyen, Huu Hung, et al.
Published: (2025)
A Universal System for OpenID Connect Sign-ins with Verifiable Credentials and Cross-Device Flow
by: Hoops, Felix, et al.
Published: (2024)
by: Hoops, Felix, et al.
Published: (2024)
Aligning Security Compliance and DevOps: A Longitudinal Study
by: Moyón, Fabiola, et al.
Published: (2025)
by: Moyón, Fabiola, et al.
Published: (2025)
An Industry Interview Study of Software Signing for Supply Chain Security
by: Kalu, Kelechi G., et al.
Published: (2024)
by: Kalu, Kelechi G., et al.
Published: (2024)
Why Johnny Adopts Identity-Based Software Signing: A Usability Case Study of Sigstore
by: Kalu, Kelechi G., et al.
Published: (2025)
by: Kalu, Kelechi G., et al.
Published: (2025)
Expert-in-the-Loop Systems with Cross-Domain and In-Domain Few-Shot Learning for Software Vulnerability Detection
by: Farr, David, et al.
Published: (2025)
by: Farr, David, et al.
Published: (2025)
Vulnerability Patching Across Software Products and Software Components: A Case Study of Red Hat's Product Portfolio
by: Ruohonen, Jukka, et al.
Published: (2025)
by: Ruohonen, Jukka, et al.
Published: (2025)
On the GitHub Actions Language: Usage, Evolution, and Workflow Reliability
by: Bardsiri, Aref Talebzadeh, et al.
Published: (2026)
by: Bardsiri, Aref Talebzadeh, et al.
Published: (2026)
Mapping NVD Records to Their Vulnerability-fixing Commits: How Hard is It?
by: Nguyen, Huu Hung, et al.
Published: (2025)
by: Nguyen, Huu Hung, et al.
Published: (2025)
RepoMark: A Data-Usage Auditing Framework for Code Large Language Models
by: Qu, Wenjie, et al.
Published: (2025)
by: Qu, Wenjie, et al.
Published: (2025)
MAS-SZZ: Multi-Agentic SZZ Algorithm for Vulnerability-Inducing Commit Identification
by: Cao, Sicong, et al.
Published: (2026)
by: Cao, Sicong, et al.
Published: (2026)
SCRUTINEER: Detecting Logic-Level Usage Violations of Reusable Components in Smart Contracts
by: Lin, Xingshuang, et al.
Published: (2025)
by: Lin, Xingshuang, et al.
Published: (2025)
Models Are Codes: Towards Measuring Malicious Code Poisoning Attacks on Pre-trained Model Hubs
by: Zhao, Jian, et al.
Published: (2024)
by: Zhao, Jian, et al.
Published: (2024)
CleanVul: Automatic Function-Level Vulnerability Detection in Code Commits Using LLM Heuristics
by: Li, Yikun, et al.
Published: (2024)
by: Li, Yikun, et al.
Published: (2024)
Beyond Metadata: Code-centric and Usage-based Analysis of Known Vulnerabilities in Open-source Software
by: Ponta, Serena E., et al.
Published: (2018)
by: Ponta, Serena E., et al.
Published: (2018)
Establishing Provenance Before Coding: Traditional and Next-Gen Software Signing
by: Schorlemmer, Taylor R., et al.
Published: (2024)
by: Schorlemmer, Taylor R., et al.
Published: (2024)
GitHub Proxy Server: A tool for supporting massive data collection on GitHub
by: Borges, Hudson Silva, et al.
Published: (2025)
by: Borges, Hudson Silva, et al.
Published: (2025)
Signing in Four Public Software Package Registries: Quantity, Quality, and Influencing Factors
by: Schorlemmer, Taylor R, et al.
Published: (2024)
by: Schorlemmer, Taylor R, et al.
Published: (2024)
DiVerify: Hardening Identity-Based Software Signing with Diverse-Context Scopes
by: Okafor, Chinenye, et al.
Published: (2024)
by: Okafor, Chinenye, et al.
Published: (2024)
Similar Items
-
Exploring User Privacy Awareness on GitHub: An Empirical Study
by: Alfieri, Costanza, et al.
Published: (2024) -
Least Privilege Access for Persistent Storage Mechanisms in Web Browsers
by: Kancherla, Gayatri Priyadarsini, et al.
Published: (2024) -
Unpacking Security Scanners for GitHub Actions Workflows
by: Fares, Madjda, et al.
Published: (2026) -
On the effectiveness of Large Language Models for GitHub Workflows
by: Zhang, Xinyu, et al.
Published: (2024) -
Security Weaknesses of Copilot-Generated Code in GitHub Projects: An Empirical Study
by: Fu, Yujia, et al.
Published: (2023)