diff --git a/.github/CONTRIBUTING.md b/.github/CONTRIBUTING.md index ed6038d..5006692 100644 --- a/.github/CONTRIBUTING.md +++ b/.github/CONTRIBUTING.md @@ -119,3 +119,20 @@ We follow [Conventional Commits](https://www.conventionalcommits.org/): [optional body] [optional footer] + +## Signed commits + +Every commit that reaches the default branch must be signed; a ruleset refuses +unsigned pushes. Estate policy: +[SIGNING-POLICY](https://github.com/hyperpolymath/standards/blob/main/docs/SIGNING-POLICY.adoc). + +- **People and interactive agents** sign with an SSH key registered on GitHub + as a *signing* key (`gpg.format=ssh`, `user.signingkey=.pub`, + `commit.gpgsign=true`). The committer email must be verified on that account. +- **Apps, bots and workflows** never `git push` local commits. They write + through the API (`createCommitOnBranch` or the estate `signed-push` action) + so that GitHub signs each commit. +- Merge PRs with **squash**. The ruleset checks every commit on the PR branch, + not just the result, so one unsigned commit blocks the merge. Re-create such a + branch with signed commits (`git cherry-pick -S`) and open a new PR. + Rebase-merge is enabled in the tracked repository settings. The repository still requires signed commits on the default branch. diff --git a/CONTRIBUTING.adoc b/CONTRIBUTING.adoc index 5949bf0..bb1a67d 100644 --- a/CONTRIBUTING.adoc +++ b/CONTRIBUTING.adoc @@ -7,3 +7,23 @@ . Submit a pull request *Author:* Jonathan D.A. Jewell j.d.a.jewell@open.ac.uk + +== Signed commits + +Every commit that reaches the default branch must be signed; a ruleset refuses +unsigned pushes. Estate policy: +https://github.com/hyperpolymath/standards/blob/main/docs/SIGNING-POLICY.adoc[SIGNING-POLICY]. + +* **People and interactive agents** sign with an SSH key registered on GitHub + as a *signing* key (`gpg.format=ssh`, `user.signingkey=.pub`, + `commit.gpgsign=true`). The committer email must be verified on that account. +* **Apps, bots and workflows** never `git push` local commits. They write + through the API (`createCommitOnBranch` or the estate `signed-push` action) + so that GitHub signs each commit. +* Merge PRs with **squash**. The ruleset checks every commit on the PR branch, + not just the result, so one unsigned commit blocks the merge. Rewrite the PR + branch with signed commits (`git cherry-pick -S`), or squash and sign it + locally, then push the updated branch. Create a new PR only when the existing + PR branch cannot be rewritten. + Rebase-merge is enabled in the tracked repository settings. The repository + still requires signed commits on the default branch.