Skip to content

Commit ac9aee9

Browse files
docs: add Signed commits section to CONTRIBUTING
Owner ruling D218. See docs/SIGNING-POLICY.adoc in hyperpolymath/standards. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01WRvDivYwLSeVCJUrfjic3f
1 parent d5063d8 commit ac9aee9

1 file changed

Lines changed: 17 additions & 0 deletions

File tree

‎CONTRIBUTING.adoc‎

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -50,3 +50,20 @@ protection requires review and passing checks.
5050
packaging policy, secrets, licence consistency and workflow security.
5151
. Security issues: follow `+SECURITY.md+` — report privately, never in a
5252
public issue.
53+
54+
== Signed commits
55+
56+
Every commit that reaches the default branch must be signed; a ruleset refuses
57+
unsigned pushes. Estate policy:
58+
https://github.com/hyperpolymath/standards/blob/main/docs/SIGNING-POLICY.adoc[SIGNING-POLICY].
59+
60+
* **People and interactive agents** sign with an SSH key registered on GitHub
61+
as a *signing* key (`gpg.format=ssh`, `user.signingkey=<key>.pub`,
62+
`commit.gpgsign=true`). The committer email must be verified on that account.
63+
* **Apps, bots and workflows** never `git push` local commits. They write
64+
through the API (`createCommitOnBranch` or the estate `signed-push` action)
65+
so that GitHub signs each commit.
66+
* Merge PRs with **squash**. The ruleset checks every commit on the PR branch,
67+
not just the result, so one unsigned commit blocks the merge. Re-create such a
68+
branch with signed commits (`git cherry-pick -S`) and open a new PR.
69+
Rebase-merge replays commits unsigned and is disabled.

0 commit comments

Comments
 (0)