From 15f65f1087159d6a57ce92c248feedbf5668fb2e Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Wed, 30 Sep 2026 23:22:31 +0100 Subject: [PATCH 1/4] docs: add Signed commits section to CONTRIBUTING Owner ruling D218. See docs/SIGNING-POLICY.adoc in hyperpolymath/standards. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01WRvDivYwLSeVCJUrfjic3f --- .github/CONTRIBUTING.md | 15 +++++++++++++++ CONTRIBUTING.adoc | 15 +++++++++++++++ 2 files changed, 30 insertions(+) diff --git a/.github/CONTRIBUTING.md b/.github/CONTRIBUTING.md index dd08e0c..65686cc 100644 --- a/.github/CONTRIBUTING.md +++ b/.github/CONTRIBUTING.md @@ -90,3 +90,18 @@ documentation and prose. This is a sole-maintainer project; the maintainer reviews all contributions. Significant or structural changes should be discussed in an issue first (see GOVERNANCE.adoc). + +## Signed Commits + +Every commit that reaches the default branch must be signed; a ruleset refuses +unsigned pushes. Estate policy: +[SIGNING-POLICY](https://github.com/hyperpolymath/standards/blob/main/docs/SIGNING-POLICY.adoc). + +- **People and interactive agents** sign with an SSH key registered on GitHub + as a *signing* key (`gpg.format=ssh`, `commit.gpgsign=true`). The committer + email must be verified on that account. +- **Apps, bots and workflows** never `git push` local commits. They write + through the API (`createCommitOnBranch`, the estate `signed-push` action, or a + squash merge) so that GitHub signs the commit. +- Merge PRs with **squash**. Rebase-merge replays commits unsigned and is + disabled. diff --git a/CONTRIBUTING.adoc b/CONTRIBUTING.adoc index 246b5e2..98431c5 100644 --- a/CONTRIBUTING.adoc +++ b/CONTRIBUTING.adoc @@ -56,3 +56,18 @@ This root document exists because the estate docs gate `CONTRIBUTING.md`, `CONTRIBUTING.adoc`, or `3-practice/CONTRIBUTING.adoc` at the repository root. Estate documentation policy: AsciiDoc by default — see `hyperpolymath/standards`. + +== Signed commits + +Every commit that reaches the default branch must be signed; a ruleset refuses +unsigned pushes. Estate policy: +https://github.com/hyperpolymath/standards/blob/main/docs/SIGNING-POLICY.adoc[SIGNING-POLICY]. + +* **People and interactive agents** sign with an SSH key registered on GitHub + as a *signing* key (`gpg.format=ssh`, `commit.gpgsign=true`). The committer + email must be verified on that account. +* **Apps, bots and workflows** never `git push` local commits. They write + through the API (`createCommitOnBranch`, the estate `signed-push` action, or a + squash merge) so that GitHub signs the commit. +* Merge PRs with **squash**. Rebase-merge replays commits unsigned and is + disabled. From 10ec7d70f9293107592616242568b520676ad668 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Wed, 30 Sep 2026 23:27:04 +0100 Subject: [PATCH 2/4] docs: correct Signed commits section Owner ruling D218. See docs/SIGNING-POLICY.adoc in hyperpolymath/standards. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01WRvDivYwLSeVCJUrfjic3f --- .github/CONTRIBUTING.md | 12 +++++++----- CONTRIBUTING.adoc | 10 ++++++---- 2 files changed, 13 insertions(+), 9 deletions(-) diff --git a/.github/CONTRIBUTING.md b/.github/CONTRIBUTING.md index 65686cc..9859a18 100644 --- a/.github/CONTRIBUTING.md +++ b/.github/CONTRIBUTING.md @@ -91,7 +91,7 @@ This is a sole-maintainer project; the maintainer reviews all contributions. Significant or structural changes should be discussed in an issue first (see GOVERNANCE.adoc). -## Signed Commits +## Signed commits Every commit that reaches the default branch must be signed; a ruleset refuses unsigned pushes. Estate policy: @@ -101,7 +101,9 @@ unsigned pushes. Estate policy: as a *signing* key (`gpg.format=ssh`, `commit.gpgsign=true`). The committer email must be verified on that account. - **Apps, bots and workflows** never `git push` local commits. They write - through the API (`createCommitOnBranch`, the estate `signed-push` action, or a - squash merge) so that GitHub signs the commit. -- Merge PRs with **squash**. Rebase-merge replays commits unsigned and is - disabled. + through the API (`createCommitOnBranch` or the estate `signed-push` action) + so that GitHub signs each commit. +- Merge PRs with **squash**. The ruleset checks every commit on the PR branch, + not just the result, so one unsigned commit blocks the merge. Re-create such a + branch with signed commits (`git cherry-pick -S`) and open a new PR. + Rebase-merge replays commits unsigned and is disabled. diff --git a/CONTRIBUTING.adoc b/CONTRIBUTING.adoc index 98431c5..f2e66ae 100644 --- a/CONTRIBUTING.adoc +++ b/CONTRIBUTING.adoc @@ -67,7 +67,9 @@ https://github.com/hyperpolymath/standards/blob/main/docs/SIGNING-POLICY.adoc[SI as a *signing* key (`gpg.format=ssh`, `commit.gpgsign=true`). The committer email must be verified on that account. * **Apps, bots and workflows** never `git push` local commits. They write - through the API (`createCommitOnBranch`, the estate `signed-push` action, or a - squash merge) so that GitHub signs the commit. -* Merge PRs with **squash**. Rebase-merge replays commits unsigned and is - disabled. + through the API (`createCommitOnBranch` or the estate `signed-push` action) + so that GitHub signs each commit. +* Merge PRs with **squash**. The ruleset checks every commit on the PR branch, + not just the result, so one unsigned commit blocks the merge. Re-create such a + branch with signed commits (`git cherry-pick -S`) and open a new PR. + Rebase-merge replays commits unsigned and is disabled. From e4472b0597a5d67e2972670aad7503ef906ded37 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Wed, 30 Sep 2026 23:46:57 +0100 Subject: [PATCH 3/4] docs: align existing signing guidance with SSH-for-people Owner ruling D218. See docs/SIGNING-POLICY.adoc in hyperpolymath/standards. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01WRvDivYwLSeVCJUrfjic3f --- .github/CONTRIBUTING.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/CONTRIBUTING.md b/.github/CONTRIBUTING.md index 9859a18..a60d967 100644 --- a/.github/CONTRIBUTING.md +++ b/.github/CONTRIBUTING.md @@ -75,7 +75,7 @@ source (vendor KB, Event ID, registry key) where you can. 4. Run the relevant checks locally (`just` `prove`, `just` `abi-check`, `cargo` `test`, `zig` `build` `test`). -5. Sign your commits (SSH or GPG). +5. Sign your commits with SSH (see Signed commits). 6. Follow [Conventional Commits](https://www.conventionalcommits.org/). From cd65c349575422e1dbe3f31f1d9898dcca672e34 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Thu, 1 Oct 2026 00:06:17 +0100 Subject: [PATCH 4/4] docs: align Signed commits section with SSH-for-people and heading level Owner ruling D218. See docs/SIGNING-POLICY.adoc in hyperpolymath/standards. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01WRvDivYwLSeVCJUrfjic3f --- .github/CONTRIBUTING.md | 4 ++-- CONTRIBUTING.adoc | 4 ++-- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/.github/CONTRIBUTING.md b/.github/CONTRIBUTING.md index a60d967..4922472 100644 --- a/.github/CONTRIBUTING.md +++ b/.github/CONTRIBUTING.md @@ -98,8 +98,8 @@ unsigned pushes. Estate policy: [SIGNING-POLICY](https://github.com/hyperpolymath/standards/blob/main/docs/SIGNING-POLICY.adoc). - **People and interactive agents** sign with an SSH key registered on GitHub - as a *signing* key (`gpg.format=ssh`, `commit.gpgsign=true`). The committer - email must be verified on that account. + as a *signing* key (`gpg.format=ssh`, `user.signingkey=.pub`, + `commit.gpgsign=true`). The committer email must be verified on that account. - **Apps, bots and workflows** never `git push` local commits. They write through the API (`createCommitOnBranch` or the estate `signed-push` action) so that GitHub signs each commit. diff --git a/CONTRIBUTING.adoc b/CONTRIBUTING.adoc index f2e66ae..60a6ad3 100644 --- a/CONTRIBUTING.adoc +++ b/CONTRIBUTING.adoc @@ -64,8 +64,8 @@ unsigned pushes. Estate policy: https://github.com/hyperpolymath/standards/blob/main/docs/SIGNING-POLICY.adoc[SIGNING-POLICY]. * **People and interactive agents** sign with an SSH key registered on GitHub - as a *signing* key (`gpg.format=ssh`, `commit.gpgsign=true`). The committer - email must be verified on that account. + as a *signing* key (`gpg.format=ssh`, `user.signingkey=.pub`, + `commit.gpgsign=true`). The committer email must be verified on that account. * **Apps, bots and workflows** never `git push` local commits. They write through the API (`createCommitOnBranch` or the estate `signed-push` action) so that GitHub signs each commit.