docs: add Signed commits section to CONTRIBUTING - #114
Conversation
Owner ruling D218. See docs/SIGNING-POLICY.adoc in hyperpolymath/standards. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01WRvDivYwLSeVCJUrfjic3f
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📜 Recent review details⏰ Context from checks skipped due to timeout. (24)
|
| Layer / File(s) | Summary |
|---|---|
Signing and merge instructions .github/CONTRIBUTING.md |
The guide explains signing commits with a registered SSH key and verified committer email. It describes API-based commits for apps, bots, and workflows, squash merges, and how unsigned PR-branch commits affect merging. |
Priority: ⬇️ Low
Estimated code review effort: 2 (Simple) | ~5 minutes
Change: Other
Merge Risk: ⚪ Minimal · up to c3246
This docs-only change adds signed-commit and squash-merge guidance to the contribution guide. It does not alter runtime behavior, so merge risk is minimal.
Security Architecture Review
Security architecture risk: 🔵 Low · up to c3246
The change adds documentation, not enforcement code. No introduced or worsened security weakness was established, but the claimed merge restrictions remain only partly verified.
Retained concerns
No architecture-level concerns identified.
Security review details
Security Findings and Attack Paths
- observed — The supplied security assessment contains no retained findings. Its signing-policy candidate remains deferred, with unknown reachability; it does not establish that this documentation change enables unsigned commits to reach the default branch.
Trust Boundaries and Controls
- observed — The pre-existing local check verifies only HEAD. It does not demonstrate the guide's claimed enforcement over every PR-branch commit or its assertion that rebase merging is disabled; those depend on external configuration not established by the inspected source.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
| Check name | Status | Explanation |
|---|---|---|
| Title check | ✅ Passed | The title clearly identifies the documentation change and matches the main change in the pull request. |
| Description check | ✅ Passed | The description directly explains the signed-commit guidance added to CONTRIBUTING and matches the documented changes. |
| Docstring Coverage | ✅ Passed | No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0… |
| Linked Issues check | ✅ Passed | Check skipped because no linked issues were found for this pull request. |
| Out of Scope Changes check | ✅ Passed | Check skipped because no linked issues were found for this pull request. |
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
- Commit to this branch
- Create a new PR
- Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts
Autopilot is currently an internal CodeRabbit preview.
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.
A rabbit signs a commit with care,
An SSH key takes it there.
Squash merges keep the branches neat,
Verified emails make the feat.
The guide now shows the way to go.
Comment @coderabbitai help to get the list of available commands.
Adds a Signed commits section to this repo's CONTRIBUTING, per owner ruling D218. The estate policy is
docs/SIGNING-POLICY.adocin hyperpolymath/standards.This repo's default branch is covered by the zero-bypass
Require-Signed-Commitsruleset, and rebase-merge is off. The section tells contributors what that requires:If the file already had its own signing section, that section is replaced in place instead of adding a second one. Lines elsewhere that told people to sign with GPG are changed to match the policy (SSH for people).
This is a docs-only change. The commit was created through
createCommitOnBranch, so GitHub signs it.🤖 Generated with Claude Code
https://claude.ai/code/session_01WRvDivYwLSeVCJUrfjic3f