Skip to content

docs: correct Signed commits section (squash does not sign bot commits) - #98

Merged
hyperpolymath merged 1 commit into
mainfrom
docs/signing-policy-d218-fix
Sep 30, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
docs/signing-policy-d218-fix

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Corrects the Signed commits section added to this repo's CONTRIBUTING under owner ruling D218.

The first version said a squash merge is one way for apps and bots to get signed commits. That is wrong. GitHub signs the squash commit, but required_signatures checks every commit on the PR branch before it allows the merge. A single unsigned commit on the head blocks the PR; this was measured on pons-asinorum #46, where gh pr merge --squash was refused with "base branch policy prohibits". CodeRabbit flagged the same point on rpa-elysium#142.

The corrected section:

  • drops "or a squash merge" from the ways bots can get signed commits; the API (createCommitOnBranch) and the estate signed-push action remain;
  • says the ruleset checks every commit on the PR branch, and explains how to recover (re-create the branch with git cherry-pick -S and open a new PR).

This is a docs-only change. The commit was created through createCommitOnBranch, so GitHub signs it.

🤖 Generated with Claude Code

https://claude.ai/code/session_01WRvDivYwLSeVCJUrfjic3f

Owner ruling D218. See docs/SIGNING-POLICY.adoc in hyperpolymath/standards.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WRvDivYwLSeVCJUrfjic3f
@coderabbitai

coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 8c4d3443-a17e-4651-918f-51cfb1b9a32c

📥 Commits

Reviewing files that changed from the base of the PR and between c6dcd1b and 7d7f2ae.

📒 Files selected for processing (1)
  • .github/CONTRIBUTING.md
 ________________________________________________
< If this were a race, you'd still be importing. >
 ------------------------------------------------
  \
   \   (\__/)
       (•ㅅ•)
       /   づ
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath merged commit 9a18e26 into main Sep 30, 2026
30 of 34 checks passed
@hyperpolymath
hyperpolymath deleted the docs/signing-policy-d218-fix branch September 30, 2026 22:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant