GitHub ghost-commit smuggling TL;DR: Detached / force-pushed Git commits remain reachable via GitHub Archive / Events API — stealth exfil and provenance forgery surface. Stub — to be filled in. What it is TODO Preconditions / where it applies TODO Technique TODO Detection and defence TODO References https://instatunnel.my/blog/github-ghost-commit-smuggling-hiding-in-the-detached-head