Lots of articles state that code signing is necessary to verify the integrity of the code. If someone were to tamper with the code, this can be prevented?
This article talks about code signing being introduced as a feature: Signed commits
But how does one tamper with the code in the first place?
If a developer commits the code and pushes it to Bitbucket or GIT repository, it will be safe there. What is the point at which an attacker can tamper with the code?
If the answer is: After the commit and before the push, that can happen in other ways as well. After the file is edited by the developer, an attacker may modify it. The developer will end up committing and pushing the corrupted file.
After the file is pushed, can somebody modify it on the filesystem of the source control server?
If the file is modified on the filesystem of bitbucket, does bitbucket detect it immediately and log it as error or warning?
I am just trying to understand the scenario that necessitates code signing.