{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,24]],"date-time":"2025-12-24T08:55:24Z","timestamp":1766566524042,"version":"3.48.0"},"publisher-location":"New York, NY, USA","reference-count":36,"publisher":"ACM","funder":[{"name":"Prime Minister\u2019s Research Fellowship","award":["1702710"],"award-info":[{"award-number":["1702710"]}]},{"name":"Science and Engineering Research Board-SRG","award":["NA"],"award-info":[{"award-number":["NA"]}]},{"name":"Google India Research Award","award":["NA"],"award-info":[{"award-number":["NA"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,6,17]]},"DOI":"10.1145\/3756681.3756959","type":"proceedings-article","created":{"date-parts":[[2025,12,24]],"date-time":"2025-12-24T08:30:04Z","timestamp":1766565004000},"page":"360-370","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["On the Prevalence and Usage of Commit Signing on GitHub"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-3443-4646","authenticated-orcid":false,"given":"Anupam","family":"Sharma","sequence":"first","affiliation":[{"name":"Indian Institute of Technology Gandhinagar, Gandhinagar, Gujarat, India"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5578-0396","authenticated-orcid":false,"given":"Sreyashi","family":"Karmakar","sequence":"additional","affiliation":[{"name":"Indian Institute of Technology Gandhinagar, Gandhinagar, Gujarat, India"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1842-9353","authenticated-orcid":false,"given":"Gayatri Priyadarsini","family":"Kancherla","sequence":"additional","affiliation":[{"name":"Indian Institute of Technology Gandhinagar, Gandhinagar, Gujarat, India"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3075-2743","authenticated-orcid":false,"given":"Abhishek","family":"Bichhawat","sequence":"additional","affiliation":[{"name":"Indian Institute of Technology Gandhinagar, Gandhinagar, Gujarat, India"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,12,24]]},"reference":[{"key":"e_1_3_3_3_2_2","volume-title":"China, GitHub and the man-in-the-middle | GreatFire Analyzer \u2014 en.greatfire.org","year":"2013","unstructured":"2013. China, GitHub and the man-in-the-middle | GreatFire Analyzer \u2014 en.greatfire.org. Retrieved October 10, 2024 from https:\/\/en.greatfire.org\/blog\/2013\/jan\/china-github-and-man-middle"},{"key":"e_1_3_3_3_3_2","volume-title":"Gitstar Ranking","year":"2014","unstructured":"2014. Gitstar Ranking. https:\/\/gitstarranking.com\/"},{"key":"e_1_3_3_3_4_2","volume-title":"Flag unsigned commits with vigilant mode \u2014 GitHub Changelog","year":"2021","unstructured":"2021. Flag unsigned commits with vigilant mode \u2014 GitHub Changelog. Retrieved December 12, 2024 from https:\/\/github.blog\/changelog\/2021-04-28-flag-unsigned-commits-with-vigilant-mode\/"},{"key":"e_1_3_3_3_5_2","doi-asserted-by":"publisher","DOI":"10.1145\/3196494.3196523"},{"key":"e_1_3_3_3_6_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-25980-0_4"},{"key":"e_1_3_3_3_7_2","doi-asserted-by":"publisher","unstructured":"D Arkhipkin W Betts Jerome Lauret and A Shiryaev. 2008. An SSH key management system: Easing the pain of managing key\/user\/account associations. Journal of Physics: Conference Series 119 (07 2008). 10.1088\/1742-6596\/119\/7\/072005","DOI":"10.1088\/1742-6596\/119\/7\/072005"},{"key":"e_1_3_3_3_8_2","unstructured":"LLC Axosoft. 2025. GitKraken Legendary Git Tools. https:\/\/desktop.github.com\/."},{"key":"e_1_3_3_3_9_2","unstructured":"Felix\u00a0Rej Bottolfsen. 2024. Investigation of Commit Spoofing. Master\u2019s thesis. NTNU."},{"key":"e_1_3_3_3_10_2","doi-asserted-by":"publisher","DOI":"10.14722\/madweb.2022.23001"},{"key":"e_1_3_3_3_11_2","unstructured":"Parker\u00a0N Collier. 2024. A Quantitative Analysis of Security Keys and Commit Signing on Github. (2024)."},{"key":"e_1_3_3_3_12_2","unstructured":"Mike Doyle. 2022. Demystifying the Pl0x GitHub attack. https:\/\/www.arnica.io\/blog\/demystifying-the-pl0x-github-attack."},{"key":"e_1_3_3_3_13_2","doi-asserted-by":"publisher","DOI":"10.1145\/3510003.3510150"},{"key":"e_1_3_3_3_14_2","unstructured":"Git. 2025. Git\u2013distributed-even-if-your-workflow-isnt. https:\/\/git-scm.com."},{"key":"e_1_3_3_3_15_2","volume-title":"Build software better, together \u2014 github.com","unstructured":"GitHub. [n. d.]. Build software better, together \u2014 github.com. Retrieved October 10, 2024 from https:\/\/github.com\/about"},{"key":"e_1_3_3_3_16_2","volume-title":"GitHub event types \u2014 GitHub Docs","year":"2022","unstructured":"GitHub. 2022. GitHub event types \u2014 GitHub Docs. Retrieved October 10, 2024 from https:\/\/docs.github.com\/en\/rest\/using-the-rest-api\/github-event-types?apiVersion=2022-11-28"},{"key":"e_1_3_3_3_17_2","volume-title":"REST API endpoints for commits \u2014 GitHub Docs","year":"2022","unstructured":"GitHub. 2022. REST API endpoints for commits \u2014 GitHub Docs. Retrieved October 10, 2024 from https:\/\/docs.github.com\/en\/rest\/commits\/commits?apiVersion=2022-11-28"},{"key":"e_1_3_3_3_18_2","volume-title":"REST API endpoints for events \u2014 GitHub Docs","year":"2022","unstructured":"GitHub. 2022. REST API endpoints for events \u2014 GitHub Docs. Retrieved October 10, 2024 from https:\/\/docs.github.com\/en\/rest\/activity\/events?apiVersion=2022-11-28#about-github-events"},{"key":"e_1_3_3_3_19_2","volume-title":"REST API endpoints for pull requests \u2014 GitHub Docs","year":"2022","unstructured":"GitHub. 2022. REST API endpoints for pull requests \u2014 GitHub Docs. Retrieved October 10, 2024 from https:\/\/docs.github.com\/en\/rest\/pulls\/pulls?apiVersion=2022-11-28#about-pull-requests"},{"key":"e_1_3_3_3_20_2","unstructured":"Inc. GitHub. 2025. GitHub - Build and ship software on a single collaborative platform. https:\/\/github.com\/."},{"key":"e_1_3_3_3_21_2","unstructured":"Inc. GitHub. 2025. GitHub Desktop. https:\/\/desktop.github.com\/."},{"key":"e_1_3_3_3_22_2","volume-title":"Commit Signing with GPG","year":"2023","unstructured":"GitKraken. 2023. Commit Signing with GPG. https:\/\/help.gitkraken.com\/gitkraken-desktop\/commit-signing-with-gpg\/ Accessed: 2025-01-31."},{"key":"e_1_3_3_3_23_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE-SEIP52600.2021.00035"},{"key":"e_1_3_3_3_24_2","volume-title":"wow how come I commit in master? O_o \u00b7 rails\/rails@b839657 \u2014 github.com","author":"Homakov Egor","year":"2012","unstructured":"Egor Homakov. 2012. wow how come I commit in master? O_o \u00b7 rails\/rails@b839657 \u2014 github.com. Retrieved October 10, 2024 from https:\/\/github.com\/rails\/rails\/commit\/b83965785db1eec019edf1fc272b1aa393e6dc57"},{"key":"e_1_3_3_3_25_2","doi-asserted-by":"publisher","DOI":"10.1145\/3350546.3352519"},{"key":"e_1_3_3_3_26_2","unstructured":"GitHub Inc.2025. GitHub REST API documentation. https:\/\/docs.github.com\/en\/rest?apiVersion=2022-11-28."},{"key":"e_1_3_3_3_27_2","doi-asserted-by":"publisher","unstructured":"Apu Kapadia. 2007. A Case (Study) For Usability in Secure Email Communication. IEEE Security & Privacy 5 2 (2007) 80\u201384. 10.1109\/MSP.2007.25","DOI":"10.1109\/MSP.2007.25"},{"key":"e_1_3_3_3_28_2","doi-asserted-by":"publisher","unstructured":"Joscha Lausch Oliver Wiese and Volker Roth. 2017. What is a Secure Email?10.14722\/eurousec.2017.23022","DOI":"10.14722\/eurousec.2017.23022"},{"key":"e_1_3_3_3_29_2","unstructured":"Mark Maney. 2023. Trying to identify spoofing in GitHub? May the 4th be with you! https:\/\/www.arnica.io\/blog\/trying-to-identify-spoofing-in-github-may-the-4th-be-with-you."},{"key":"e_1_3_3_3_30_2","volume-title":"5th USENIX Workshop on Free and Open Communications on the Internet (FOCI 15)","author":"Marczak Bill","year":"2015","unstructured":"Bill Marczak, Nicholas Weaver, Jakub Dalek, Roya Ensafi, David Fifield, Sarah McKune, Arn Rey, John Scott-Railton, Ron Deibert, and Vern Paxson. 2015. An Analysis of China\u2019s \u201cGreat Cannon\u201d. In 5th USENIX Workshop on Free and Open Communications on the Internet (FOCI 15). USENIX Association, Washington, D.C.https:\/\/www.usenix.org\/conference\/foci15\/workshop-program\/presentation\/marczak"},{"key":"e_1_3_3_3_31_2","doi-asserted-by":"publisher","unstructured":"Michael Meli Matthew McNiece and Bradley Reaves. 2019. How Bad Can It Git? Characterizing Secret Leakage in Public GitHub Repositories. 10.14722\/ndss.2019.23418","DOI":"10.14722\/ndss.2019.23418"},{"key":"e_1_3_3_3_32_2","doi-asserted-by":"publisher","DOI":"10.1145\/2597073.2597117"},{"key":"e_1_3_3_3_33_2","unstructured":"Nikita Popov. 2021. Changes to Git commit workflow. https:\/\/news-web.php.net\/php.internals\/113839."},{"key":"e_1_3_3_3_34_2","volume-title":"Public Key Security Vulnerability and Mitigation \u2014 github.blog","author":"Preston-Werner Tom","year":"2012","unstructured":"Tom Preston-Werner. 2012. Public Key Security Vulnerability and Mitigation \u2014 github.blog. Retrieved October 10, 2024 from https:\/\/github.blog\/news-insights\/the-library\/public-key-security-vulnerability-and-mitigation\/"},{"key":"e_1_3_3_3_35_2","unstructured":"Scott Ruoti Jeff Andersen Daniel Zappala and Kent Seamons. 2015. Why Johnny Still Still Can\u2019t Encrypt: Evaluating the Usability of a Modern PGP Client. (10 2015)."},{"key":"e_1_3_3_3_36_2","doi-asserted-by":"publisher","unstructured":"Scott Ruoti and Kent Seamons. 2019. Johnny\u2019s Journey Toward Usable Secure Email. IEEE Security & Privacy 17 6 (2019) 72\u201376. 10.1109\/MSEC.2019.2933683","DOI":"10.1109\/MSEC.2019.2933683"},{"key":"e_1_3_3_3_37_2","first-page":"379","volume-title":"25th USENIX Security Symposium (USENIX Security 16)","author":"Torres-Arias Santiago","year":"2016","unstructured":"Santiago Torres-Arias, Anil\u00a0Kumar Ammula, Reza Curtmola, and Justin Cappos. 2016. On Omitting Commits and Committing Omissions: Preventing Git Metadata Tampering That (Re)introduces Software Vulnerabilities. In 25th USENIX Security Symposium (USENIX Security 16). USENIX Association, Austin, TX, 379\u2013395. https:\/\/www.usenix.org\/conference\/usenixsecurity16\/technical-sessions\/presentation\/torres-arias"}],"event":{"name":"EASE '25: Evaluation and Assessment in Software Engineering","location":"Istanbul Turkiye","acronym":"EASE '25"},"container-title":["Proceedings of the 29th International Conference on Evaluation and Assessment in Software Engineering"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3756681.3756959","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,24]],"date-time":"2025-12-24T08:44:09Z","timestamp":1766565849000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3756681.3756959"}},"subtitle":["A Longitudinal and Cross-Domain Study"],"short-title":[],"issued":{"date-parts":[[2025,6,17]]},"references-count":36,"alternative-id":["10.1145\/3756681.3756959","10.1145\/3756681"],"URL":"https:\/\/doi.org\/10.1145\/3756681.3756959","relation":{},"subject":[],"published":{"date-parts":[[2025,6,17]]},"assertion":[{"value":"2025-12-24","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}