Jadwal Sholat

Memuat jadwal sholatโ€ฆ

Computer Science editorial

Open AccessOA2026

A Multi-Month Study of Git Commit Signing

Three-month study with 22 computer science students reveals that friction in setup, multi-device configuration, and verification undermines the security benefits of commit signing.
Abubakar Sadiq Shittu; John Sadik; Scott Ruotiยท 2026ยท DOI 10.48550/arXiv.2608.29283

The core problem

Git commit signing, introduced in 2012, is one mechanism for establishing commit provenance in software supply chains. Despite its availability, developer-controlled adoption remains rare, and developers' experiences using it are understudied. To address this gap, the authors conducted a three-month study with senior undergraduate and graduate computer science students (n = 22), treated as proxies for junior developers. The study aimed to examine the real-world experience of adopting and using commit signing across multiple projects and devices, and to identify barriers to effective security use. The research questions focus on setup friction, routine signing, multi-device configuration, verification of anomalous commits, and developers' mental models of signing guarantees and key management.

Innovation

Almost all participants successfully signed every commit and rated routine signing positively. However, many faced friction during setup, multi-device configuration, and repository verification. Despite signing all semester, they struggled to spot anomalous commits during verification, with over a quarter finding none. Additionally, nearly half expressed at least one misconception regarding signing guarantees or key management. These findings indicate that while signing can be adopted, effective security use is hindered by difficulties in verification and understanding.

Key quantitative outcomes:
- Success rate for signing every commit: almost all participants.
- Participants who found no anomalous commits: >25%.
- Participants with at least one misconception: ~50%.

Git commit signing, introduced in 2012, is one mechanism for establishing commit provenance in software supply chains. Despite its availability, developer-controlled adoption remains rare, and developers' experiences using it are understudied. To address this gap, the authors conducted a three-month study with senior undergraduate and graduate computer science students (n = 22), treated as proxies for junior developers. The study aimed to examine the real-world experience of adopting and using commit signing across multiple projects and devices, and to identify barriers to effective security use. The research questions focus on setup friction, routine signing, multi-device configuration, verification of anomalous commits, and developers' mental models of signing guarantees and key management.
The study employed a longitudinal design over three months. Participants (n = 22) were senior undergraduate and graduate computer science students. They were asked to:

Why it matters

The study concludes that making signing easier is not enough to ensure effective security use. Secure adoption also requires tools and education that support signature verification against authorized identities, interpretation of missing signatures and unknown keys, and correct reasoning about key-lifecycle operations. The authors note that without isolating whether these difficulties stemmed from tooling, education, or understanding, the results highlight a need for holistic improvements. The findings suggest that developers may sign commits without fully grasping the security guarantees, leading to a false sense of security. Future work should explore interventions that address verification and key management education.

A conceptual model of the factors influencing effective commit signing is depicted below:

Who should read this

CS practitioners and researchers

Opening member contentโ€ฆ