Research tied to signed commits suggests that a trusted-looking hash can change while GitHub still shows “Verified,” forcing teams to rethink what their review process really proves.