File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change @@ -123,3 +123,20 @@ We follow [Conventional Commits](https://www.conventionalcommits.org/):
123123[ optional body]
124124
125125[ optional footer]
126+
127+ ## Signed commits
128+
129+ Every commit that reaches the default branch must be signed; a ruleset refuses
130+ unsigned pushes. Estate policy:
131+ [ SIGNING-POLICY] ( https://github.com/hyperpolymath/standards/blob/main/docs/SIGNING-POLICY.adoc ) .
132+
133+ - ** People and interactive agents** sign with an SSH key registered on GitHub
134+ as a * signing* key (` gpg.format=ssh ` , ` user.signingkey=<key>.pub ` ,
135+ ` commit.gpgsign=true ` ). The committer email must be verified on that account.
136+ - ** Apps, bots and workflows** never ` git push ` local commits. They write
137+ through the API (` createCommitOnBranch ` or the estate ` signed-push ` action)
138+ so that GitHub signs each commit.
139+ - Merge PRs with ** squash** . The ruleset checks every commit on the PR branch,
140+ not just the result, so one unsigned commit blocks the merge. Re-create such a
141+ branch with signed commits (` git cherry-pick -S ` ) and open a new PR.
142+ Rebase-merge replays commits unsigned and is disabled.
Original file line number Diff line number Diff line change 77. Submit a pull request
88
99*Author:* Jonathan D.A. Jewell j.d.a.jewell@open.ac.uk
10+
11+ == Signed commits
12+
13+ Every commit that reaches the default branch must be signed; a ruleset refuses
14+ unsigned pushes. Estate policy:
15+ https://github.com/hyperpolymath/standards/blob/main/docs/SIGNING-POLICY.adoc[SIGNING-POLICY].
16+
17+ * **People and interactive agents** sign with an SSH key registered on GitHub
18+ as a *signing* key (`gpg.format=ssh`, `user.signingkey=<key>.pub`,
19+ `commit.gpgsign=true`). The committer email must be verified on that account.
20+ * **Apps, bots and workflows** never `git push` local commits. They write
21+ through the API (`createCommitOnBranch` or the estate `signed-push` action)
22+ so that GitHub signs each commit.
23+ * Merge PRs with **squash**. The ruleset checks every commit on the PR branch,
24+ not just the result, so one unsigned commit blocks the merge. Re-create such a
25+ branch with signed commits (`git cherry-pick -S`) and open a new PR.
26+ Rebase-merge replays commits unsigned and is disabled.
Original file line number Diff line number Diff line change @@ -123,3 +123,20 @@ We follow [Conventional Commits](https://www.conventionalcommits.org/):
123123[ optional body]
124124
125125[ optional footer]
126+
127+ ## Signed commits
128+
129+ Every commit that reaches the default branch must be signed; a ruleset refuses
130+ unsigned pushes. Estate policy:
131+ [ SIGNING-POLICY] ( https://github.com/hyperpolymath/standards/blob/main/docs/SIGNING-POLICY.adoc ) .
132+
133+ - ** People and interactive agents** sign with an SSH key registered on GitHub
134+ as a * signing* key (` gpg.format=ssh ` , ` user.signingkey=<key>.pub ` ,
135+ ` commit.gpgsign=true ` ). The committer email must be verified on that account.
136+ - ** Apps, bots and workflows** never ` git push ` local commits. They write
137+ through the API (` createCommitOnBranch ` or the estate ` signed-push ` action)
138+ so that GitHub signs each commit.
139+ - Merge PRs with ** squash** . The ruleset checks every commit on the PR branch,
140+ not just the result, so one unsigned commit blocks the merge. Re-create such a
141+ branch with signed commits (` git cherry-pick -S ` ) and open a new PR.
142+ Rebase-merge replays commits unsigned and is disabled.
You can’t perform that action at this time.
0 commit comments