[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-84077-en":3,"doc-seo-84077-105":30,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},84077,1099514067415,"Rowan","https://ap-avatar.wpscdn.com/avatar/100002539d78ffe74a7?x-image-process=image/resize,m_fixed,w_180,h_180&k=1779092875211072502",8,"Research & Report","Claimed or Attested? A Commit-Signature Dataset and Identity Trust Tiers across the World of Code","An author string in a Git commit is unverified free text, so identity resolution across a global code corpus often rests on claims that the commit itself cannot corroborate. Cryptographic commit signing binds the commit to a key controlled by the committer; when that key maps to a real-world identity, the Git identity becomes attested. This work releases the first commit-signature axis for the World of Code, extracted from V2604 commit tables without re-reading the object database, and introduces per-commit signatures plus attestation trust tiers.","Claimed or Attested?  \nA Commit-Signature Dataset and Identity Trust Tiers across the  \nWorld of Code  \nAudris Mockus  \nUniversity of Tennessee, Knoxville  \nKnoxville, TN, USA  \n[audris@utk.edu](audris@utk.edu)  \narXiv :2607 .06 194v 1 [ cs .CR] 7 Jul 2026  \nAbstract  \nAn author string in a git commit is free text the committer typed, so identity resolution over a global commit corpus rests on a claim that nothing in the commit verifies. A cryptographically signed commit is different: it binds the commit to a key the committer controls, and when that key ties back to a real-world identity the git identity becomes attested rather than merely claimed. We release the first commit-signature axis for the World of Code (WoC), extracted for the V2604 collection. The signature travels in the commit object’sgpgsig header and is already carried, unparsed, in the commitmessage field of the WoC commit tables, so the axis is a scan over existing tables rather than a re-read of the object database. Over the V2604 corpus of 5,866,595,698 commits, 17. 59% carry a signature (PGP dominant at 98. 96%, with a growing minority of SSH and X.509/sigstore signatures), or 1,031,721,316 signed commits. We release the per-commit signature map c2sigFull, a key-to-author graph gated so that shared organization and continuous-integration keys are separated from person keys, and A2trust, a per-identity attestation tier (unsigned, signed, real-world-bound, cross-corpus attested) that extends the published A2cls identity-class dataset. The signature axis is a precision anchor, not a coverage layer: signed commits skew toward security-conscious developers, a population that overlaps the scholarly authors a bibliography join targets. We use the person keys to build a cryptographically grounded alias gold that calibrates the heuristic WoC alias map independently of hand-labeled pairs, and to attach an attestation provenance to science-to-software identity links. All artifacts are released as a self-contained, independently hosted replication package keyed to the WoC V2604 collection.  \nKeywords  \nWorld of Code, commit signing, GPG, SSH signatures, sigstore, developer identity, author disambiguation, cryptographic attestation, mining software repositories  \n1 Introduction  \nEvery study that mines a global commit corpus has to decide when two author strings denote the same person and when one string denotes two. The World of Code alias map, like other disambiguation systems, resolves this from co-occurrence of names, emails, and GitHub logins [1] . Those signals are useful, but they share a blind spot: the author field of a commit is free text the committer chose, so every merge and every split the map produces rests on a claim that nothing in the commit itself corroborates. Vanity strings  \nmake the gap concrete. Unrelated people commit as root, and wellknown names and addresses are reused by impostors; the WoC bad-identity stoplist literally enumerates such strings. A name in a commit is a claim, not an attestation.  \nScholarly authorship sits at the opposite corner of the same problem. A paper carries the author’s real name because reputation is the point of publishing, so impersonation is rare and the dominant error is homonymy: many people named J. Smith, or one person whose transliterated name is split across spellings. When a study links software authors to paper authors, it joins a low-impersonation, high-homonym universe to a high-impersonation, high-homonym one, and the join inherits the weaker guarantee.  \nA cryptographically signed commit changes the epistemics on the software side. Git supports signing a commit with a PGP key, an SSH key, or an X.509 certificate; the signature binds the commit content to a key the committer controls. If the key ties to a realworld identity, through a PGP user-id email, an SSH key registered on a GitHub account, or an X.509 or OIDC subject, then the git identity used on that commit is attested at the same level the pap","cbCaivCvUUEUNfag","https://ap.wps.com/l/cbCaivCvUUEUNfag","pdf",512514,5,1,6,"English","en",105,"# Introduction\n## Claimed vs. attested identities in commit corpora\n## How commit signing changes the evidence model\n## Dataset construction from existing World of Code tables\n## Released artifacts and contributions","[{\"question\":\"Why can author strings in Git commits only support identity claims rather than attestations?\",\"answer\":\"Because the author field is free text chosen by the committer, identity resolution over a global corpus relies on assumptions rather than proof contained in the commit itself.\"},{\"question\":\"What makes a cryptographically signed commit an attested identity?\",\"answer\":\"A signature binds the commit content to a key controlled by the committer; when that key is linked to a real-world identity, the identity used in the commit is attested at the same evidential level as author information in scholarly work.\"},{\"question\":\"How is the commit-signature dataset extracted from World of Code without re-reading the Git object database?\",\"answer\":\"World of Code tables already preserve the gpgsig block from the commit header by appending post-committer header lines into the message field, so signature information is obtained by scanning the existing V2604 commit tables.\"}]",1784192564,15,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":28},"claimed-or-attested-a-commit-signature-dataset-and-identity-trust-tiers-across-the-world-of-code","",{"@graph":36,"@context":86},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/claimed-or-attested-a-commit-signature-dataset-and-identity-trust-tiers-across-the-world-of-code/84077/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":24,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-07-27","2026-07-16",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"Why can author strings in Git commits only support identity claims rather than attestations?","Question",{"text":76,"@type":77},"Because the author field is free text chosen by the committer, identity resolution over a global corpus relies on assumptions rather than proof contained in the commit itself.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"What makes a cryptographically signed commit an attested identity?",{"text":81,"@type":77},"A signature binds the commit content to a key controlled by the committer; when that key is linked to a real-world identity, the identity used in the commit is attested at the same evidential level as author information in scholarly work.",{"name":83,"@type":74,"acceptedAnswer":84},"How is the commit-signature dataset extracted from World of Code without re-reading the Git object database?",{"text":85,"@type":77},"World of Code tables already preserve the gpgsig block from the commit header by appending post-committer header lines into the message field, so signature information is obtained by scanning the existing V2604 commit tables.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":93},[94,98,102,106,110,114,119,122,127,130,134],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},"Comic",60,"comic",{"id":22,"doc_module":4,"doc_module_name":46,"category_name":111,"show_sort_weight":112,"slug":113},"Technology",50,"technology",{"id":115,"doc_module":4,"doc_module_name":46,"category_name":116,"show_sort_weight":117,"slug":118},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":20,"slug":137},19,"General","general"]