A security disclosure around GitHub commit verification shows why a trusted badge can still hide a tricky identity problem for supply-chain tooling.