Skip to content

Commit fa56251

Browse files
docs: add Signed commits section to CONTRIBUTING
Owner ruling D218. See docs/SIGNING-POLICY.adoc in hyperpolymath/standards. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01WRvDivYwLSeVCJUrfjic3f
1 parent 2d7ae59 commit fa56251

3 files changed

Lines changed: 51 additions & 0 deletions

File tree

‎.github/CONTRIBUTING.md‎

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -123,3 +123,20 @@ We follow [Conventional Commits](https://www.conventionalcommits.org/):
123123
[optional body]
124124

125125
[optional footer]
126+
127+
## Signed commits
128+
129+
Every commit that reaches the default branch must be signed; a ruleset refuses
130+
unsigned pushes. Estate policy:
131+
[SIGNING-POLICY](https://github.com/hyperpolymath/standards/blob/main/docs/SIGNING-POLICY.adoc).
132+
133+
- **People and interactive agents** sign with an SSH key registered on GitHub
134+
as a *signing* key (`gpg.format=ssh`, `user.signingkey=<key>.pub`,
135+
`commit.gpgsign=true`). The committer email must be verified on that account.
136+
- **Apps, bots and workflows** never `git push` local commits. They write
137+
through the API (`createCommitOnBranch` or the estate `signed-push` action)
138+
so that GitHub signs each commit.
139+
- Merge PRs with **squash**. The ruleset checks every commit on the PR branch,
140+
not just the result, so one unsigned commit blocks the merge. Re-create such a
141+
branch with signed commits (`git cherry-pick -S`) and open a new PR.
142+
Rebase-merge replays commits unsigned and is disabled.

‎CONTRIBUTING.adoc‎

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,3 +7,20 @@
77
. Submit a pull request
88

99
*Author:* Jonathan D.A. Jewell j.d.a.jewell@open.ac.uk
10+
11+
== Signed commits
12+
13+
Every commit that reaches the default branch must be signed; a ruleset refuses
14+
unsigned pushes. Estate policy:
15+
https://github.com/hyperpolymath/standards/blob/main/docs/SIGNING-POLICY.adoc[SIGNING-POLICY].
16+
17+
* **People and interactive agents** sign with an SSH key registered on GitHub
18+
as a *signing* key (`gpg.format=ssh`, `user.signingkey=<key>.pub`,
19+
`commit.gpgsign=true`). The committer email must be verified on that account.
20+
* **Apps, bots and workflows** never `git push` local commits. They write
21+
through the API (`createCommitOnBranch` or the estate `signed-push` action)
22+
so that GitHub signs each commit.
23+
* Merge PRs with **squash**. The ruleset checks every commit on the PR branch,
24+
not just the result, so one unsigned commit blocks the merge. Re-create such a
25+
branch with signed commits (`git cherry-pick -S`) and open a new PR.
26+
Rebase-merge replays commits unsigned and is disabled.

‎CONTRIBUTING.md‎

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -123,3 +123,20 @@ We follow [Conventional Commits](https://www.conventionalcommits.org/):
123123
[optional body]
124124

125125
[optional footer]
126+
127+
## Signed commits
128+
129+
Every commit that reaches the default branch must be signed; a ruleset refuses
130+
unsigned pushes. Estate policy:
131+
[SIGNING-POLICY](https://github.com/hyperpolymath/standards/blob/main/docs/SIGNING-POLICY.adoc).
132+
133+
- **People and interactive agents** sign with an SSH key registered on GitHub
134+
as a *signing* key (`gpg.format=ssh`, `user.signingkey=<key>.pub`,
135+
`commit.gpgsign=true`). The committer email must be verified on that account.
136+
- **Apps, bots and workflows** never `git push` local commits. They write
137+
through the API (`createCommitOnBranch` or the estate `signed-push` action)
138+
so that GitHub signs each commit.
139+
- Merge PRs with **squash**. The ruleset checks every commit on the PR branch,
140+
not just the result, so one unsigned commit blocks the merge. Re-create such a
141+
branch with signed commits (`git cherry-pick -S`) and open a new PR.
142+
Rebase-merge replays commits unsigned and is disabled.

0 commit comments

Comments
 (0)