File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change 11# Contributing
22
33See [ CONTRIBUTING.adoc] ( CONTRIBUTING.adoc ) for full contribution guidelines.
4+
5+ ## Signed commits
6+
7+ Every commit that reaches the default branch must be signed; a ruleset refuses
8+ unsigned pushes. Estate policy:
9+ [ SIGNING-POLICY] ( https://github.com/hyperpolymath/standards/blob/main/docs/SIGNING-POLICY.adoc ) .
10+
11+ - ** People and interactive agents** sign with an SSH key registered on GitHub
12+ as a * signing* key (` gpg.format=ssh ` , ` user.signingkey=<key>.pub ` ,
13+ ` commit.gpgsign=true ` ). The committer email must be verified on that account.
14+ - ** Apps, bots and workflows** never ` git push ` local commits. They write
15+ through the API (` createCommitOnBranch ` or the estate ` signed-push ` action)
16+ so that GitHub signs each commit.
17+ - Merge PRs with ** squash** . The ruleset checks every commit on the PR branch,
18+ not just the result, so one unsigned commit blocks the merge. Re-create such a
19+ branch with signed commits (` git cherry-pick -S ` ) and open a new PR.
20+ Rebase-merge replays commits unsigned and is disabled.
You can’t perform that action at this time.
0 commit comments