The two paths therefore reach opposite conclusions for the same malformed commit: git verify-commit fails (raw bytes with both trees ≠signed canonical bytes), while gitsign verify succeeds ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results