From 1c10b3f13a880ea6022d3e262e984ca539bf534e Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Thu, 1 Oct 2026 06:59:27 +0100 Subject: [PATCH] docs: add Signed commits section to CONTRIBUTING Owner ruling D218. See docs/SIGNING-POLICY.adoc in hyperpolymath/standards. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01WRvDivYwLSeVCJUrfjic3f --- CONTRIBUTING.adoc | 29 +++++++++++++++++------------ 1 file changed, 17 insertions(+), 12 deletions(-) diff --git a/CONTRIBUTING.adoc b/CONTRIBUTING.adoc index 4d16160..b928556 100644 --- a/CONTRIBUTING.adoc +++ b/CONTRIBUTING.adoc @@ -151,17 +151,22 @@ Allowed types: `+feat+`, `+fix+`, `+docs+`, `+style+`, `+refactor+`, `+perf+`, `+test+`, `+build+`, `+ci+`, `+chore+`, `+revert+`, `+security+`. -==== Commit Signing - -All commits *must be GPG-signed*. Configure: - -[source,bash] ----- -git config commit.gpgsign true -git config user.signingkey ----- - -Unsigned commits will fail the `+commit-signing+` enforcement check. +==== Signed commits + +Every commit that reaches the default branch must be signed; a ruleset refuses +unsigned pushes. Estate policy: +https://github.com/hyperpolymath/standards/blob/main/docs/SIGNING-POLICY.adoc[SIGNING-POLICY]. + +* **People and interactive agents** sign with an SSH key registered on GitHub + as a *signing* key (`gpg.format=ssh`, `user.signingkey=.pub`, + `commit.gpgsign=true`). The committer email must be verified on that account. +* **Apps, bots and workflows** never `git push` local commits. They write + through the API (`createCommitOnBranch` or the estate `signed-push` action) + so that GitHub signs each commit. +* Merge PRs with **squash**. The ruleset checks every commit on the PR branch, + not just the result, so one unsigned commit blocks the merge. Re-create such a + branch with signed commits (`git cherry-pick -S`) and open a new PR. + Rebase-merge replays commits unsigned and is disabled. ==== Pull Request Checklist @@ -179,7 +184,7 @@ conventional commits via https://github.com/hyperpolymath/standards/blob/main/.github/workflows/changelog-reusable.yml[`+standards/changelog-reusable.yml+`] * [ ] SPDX header on every new source file (`+// SPDX-License-Identifier: CC-BY-SA-4.0+`) -* [ ] Commits GPG-signed +* [ ] Commits signed When opening the PR: