From 457946592f7ebc1462cbea6829ce257ab2422472 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Wed, 30 Sep 2026 23:35:18 +0100 Subject: [PATCH 1/3] docs: add Signed commits section to CONTRIBUTING Owner ruling D218. See docs/SIGNING-POLICY.adoc in hyperpolymath/standards. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01WRvDivYwLSeVCJUrfjic3f --- .github/CONTRIBUTING.md | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) diff --git a/.github/CONTRIBUTING.md b/.github/CONTRIBUTING.md index 29b8c09..a3e3d9c 100644 --- a/.github/CONTRIBUTING.md +++ b/.github/CONTRIBUTING.md @@ -122,3 +122,20 @@ We follow [Conventional Commits](https://www.conventionalcommits.org/): [optional body] [optional footer] + +### Signed commits + +Every commit that reaches the default branch must be signed; a ruleset refuses +unsigned pushes. Estate policy: +[SIGNING-POLICY](https://github.com/hyperpolymath/standards/blob/main/docs/SIGNING-POLICY.adoc). + +- **People and interactive agents** sign with an SSH key registered on GitHub + as a *signing* key (`gpg.format=ssh`, `commit.gpgsign=true`). The committer + email must be verified on that account. +- **Apps, bots and workflows** never `git push` local commits. They write + through the API (`createCommitOnBranch` or the estate `signed-push` action) + so that GitHub signs each commit. +- Merge PRs with **squash**. The ruleset checks every commit on the PR branch, + not just the result, so one unsigned commit blocks the merge. Re-create such a + branch with signed commits (`git cherry-pick -S`) and open a new PR. + Rebase-merge replays commits unsigned and is disabled. From f5745f0c09c77aa704013bfc78495a9c9bd9ba29 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Wed, 30 Sep 2026 23:54:27 +0100 Subject: [PATCH 2/3] docs: align Signed commits section with SSH-for-people and heading level Owner ruling D218. See docs/SIGNING-POLICY.adoc in hyperpolymath/standards. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01WRvDivYwLSeVCJUrfjic3f --- .github/CONTRIBUTING.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/CONTRIBUTING.md b/.github/CONTRIBUTING.md index a3e3d9c..fa12bc2 100644 --- a/.github/CONTRIBUTING.md +++ b/.github/CONTRIBUTING.md @@ -123,7 +123,7 @@ We follow [Conventional Commits](https://www.conventionalcommits.org/): [optional footer] -### Signed commits +## Signed commits Every commit that reaches the default branch must be signed; a ruleset refuses unsigned pushes. Estate policy: From 0a8cbce03b8321b0d6aa400d75cc880ff64daba2 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Thu, 1 Oct 2026 00:10:08 +0100 Subject: [PATCH 3/3] docs: align Signed commits section with SSH-for-people and heading level Owner ruling D218. See docs/SIGNING-POLICY.adoc in hyperpolymath/standards. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01WRvDivYwLSeVCJUrfjic3f --- .github/CONTRIBUTING.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/CONTRIBUTING.md b/.github/CONTRIBUTING.md index fa12bc2..9231894 100644 --- a/.github/CONTRIBUTING.md +++ b/.github/CONTRIBUTING.md @@ -130,8 +130,8 @@ unsigned pushes. Estate policy: [SIGNING-POLICY](https://github.com/hyperpolymath/standards/blob/main/docs/SIGNING-POLICY.adoc). - **People and interactive agents** sign with an SSH key registered on GitHub - as a *signing* key (`gpg.format=ssh`, `commit.gpgsign=true`). The committer - email must be verified on that account. + as a *signing* key (`gpg.format=ssh`, `user.signingkey=.pub`, + `commit.gpgsign=true`). The committer email must be verified on that account. - **Apps, bots and workflows** never `git push` local commits. They write through the API (`createCommitOnBranch` or the estate `signed-push` action) so that GitHub signs each commit.