Skip to content

docs: add Signed commits section to CONTRIBUTING - #97

Merged
hyperpolymath merged 2 commits into
mainfrom
docs/signing-policy-d218
Sep 30, 2026
Merged

hyperpolymath merged 2 commits into
mainfrom
docs/signing-policy-d218

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Adds a Signed commits section to this repo's CONTRIBUTING, per owner ruling D218. The estate policy is docs/SIGNING-POLICY.adoc in hyperpolymath/standards.

This repo's default branch is covered by the zero-bypass Require-Signed-Commits ruleset, and rebase-merge is off. The section tells contributors what that requires:

  • People and interactive agents sign with an SSH signing key.
  • Apps, bots and workflows write through the API, so GitHub signs their commits.
  • PRs are merged with squash.

This is a docs-only change. The commit was created through createCommitOnBranch, so GitHub signs it.

🤖 Generated with Claude Code

https://claude.ai/code/session_01WRvDivYwLSeVCJUrfjic3f

Owner ruling D218. See docs/SIGNING-POLICY.adoc in hyperpolymath/standards.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WRvDivYwLSeVCJUrfjic3f
@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 7 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 90b38492-da67-47ed-92af-eaa0de1307a4

📥 Commits

Reviewing files that changed from the base of the PR and between 3b5987d and 1f8ca3d.

📒 Files selected for processing (1)
  • .github/CONTRIBUTING.md

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: ee389a94-1155-4518-94c1-c26621f053bc

📥 Commits

Reviewing files that changed from the base of the PR and between 82c7247 and 3b5987d.

📒 Files selected for processing (1)
  • .github/CONTRIBUTING.md

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.

📜 Recent review details
⏰ Context from checks skipped due to timeout. (26)
  • GitHub Check: governance / Workflow security linter
  • GitHub Check: governance / Check Workflow Staleness
  • GitHub Check: governance / Security policy checks
  • GitHub Check: governance / Debt ratchet
  • GitHub Check: scan / shell-secrets
  • GitHub Check: governance / Licence consistency
  • GitHub Check: governance / Actions lockfile verify
  • GitHub Check: governance / Allowlist Preflight
  • GitHub Check: governance / Language / package anti-pattern policy
  • GitHub Check: governance / Exemption ratchet
  • GitHub Check: scan / rust-secrets
  • GitHub Check: governance / Well-Known (RFC 9116 + RSR)
  • GitHub Check: governance / Live Actions policy (credentialed advisory)
  • GitHub Check: governance / Guix packaging policy (Nix retired)
  • GitHub Check: governance / Code quality + docs
  • GitHub Check: scan / gitleaks
  • GitHub Check: governance / Trusted-base reduction policy
  • GitHub Check: hypatia / Hypatia Neurosymbolic Analysis
  • GitHub Check: check
  • GitHub Check: Check for Banned Languages
  • GitHub Check: Validate DEED manifests
  • GitHub Check: Empty-linter (invisible characters)
  • GitHub Check: Validate K9 contracts
  • GitHub Check: Check Required Files
  • GitHub Check: Groove manifest check
  • GitHub Check: deploy-now
⚠️ CI failures not shown inline (2)

GitHub Actions: Deploy Now / 0_deploy-now.txt: docs: add Signed commits section to CONTRIBUTING

Conclusion: failure

View job details

##[group]Run ionos-deploy-now/retrieve-project-info-action@v1.5.2
 with:
   api-key: ***
   project: ***
   service-host: api-eu.ionos.space
 ##[endgroup]
 (node:2159) [DEP0169] DeprecationWarning: `url.parse()` behavior is not standardized and prone to errors that have security implications. Use the WHATWG URL API instead. CVEs are not issued for `url.parse()` vulnerabilities.
 (Use `node --trace-deprecation ...` to show where the warning was created)
 ##[error]Branch docs/signing-policy-d218 not found in DeployNow

GitHub Actions: Deploy Now / deploy-now: docs: add Signed commits section to CONTRIBUTING

Conclusion: failure

View job details

##[group]Run ionos-deploy-now/retrieve-project-info-action@v1.5.2
 with:
   api-key: ***
   project: ***
   service-host: api-eu.ionos.space
 ##[endgroup]
 (node:2159) [DEP0169] DeprecationWarning: `url.parse()` behavior is not standardized and prone to errors that have security implications. Use the WHATWG URL API instead. CVEs are not issued for `url.parse()` vulnerabilities.
 (Use `node --trace-deprecation ...` to show where the warning was created)
 ##[error]Branch docs/signing-policy-d218 not found in DeployNow
🔇 Additional comments (1)
.github/CONTRIBUTING.md (1)

89-103: LGTM!


📝 Summary

Summary by CodeRabbit

  • Documentation
    • Added contributor guidance requiring signed commits on the default branch, using a GitHub-registered SSH signing key and verified committer email for people and interactive agents.
    • Explained that apps, bots and workflows must use approved API, action or squash-merge routes instead of pushing local commits.
    • Clarified that pull requests must be squash-merged; rebase-merge is disabled.

Walkthrough

The contributor guide now sets signed-commit requirements and specifies acceptable signing and submission methods. It also requires squash merges and states that rebase-merge is disabled.

Changes

Contributor commit policy

Layer / File(s) Summary
Commit signing and submission rules
.github/CONTRIBUTING.md
The guide requires signed commits and specifies signing and submission methods for people, interactive agents, apps, bots and workflows. It also requires squash merges and states that rebase-merge is disabled.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~3 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 3b598

The new guidance aligns with the verified signed-commit requirement, and no concrete contributor-workflow failure is established. Merge-method settings remain unverified, but no merge-blocking risk is evident.

Architecture Summary

Architecture risk: 🔵 Low · up to 3b598

The changed surface does not map to a changed system, dependency edge, entrypoint, or external dependency.

Changed systems: None identified.

Architecture concerns
No architecture-level concerns identified.

Review details

Before / after behavior

  • observed — Modified behavior in .github/CONTRIBUTING.md: Adds signed-commit requirements and specifies signing and submission methods for people, interactive agents, apps, bots and workflows. It also requires squash merges and states that rebase-merge is disabled.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly summarises the main change: adding a Signed commits section to CONTRIBUTING.
Description check ✅ Passed The description accurately explains the documentation change, its signing requirements, and the squash-merge policy.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit signs a commit with care,
Then sends it on through proper fare.
A squash merge brings the work to land,
While unsigned pushes meet a ban.
The guide keeps each commit in line.

Comment @coderabbitai help to get the list of available commands.

Owner ruling D218. See docs/SIGNING-POLICY.adoc in hyperpolymath/standards.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WRvDivYwLSeVCJUrfjic3f
@hyperpolymath
hyperpolymath merged commit c6dcd1b into main Sep 30, 2026
31 of 34 checks passed
@hyperpolymath
hyperpolymath deleted the docs/signing-policy-d218 branch September 30, 2026 22:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant