File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change @@ -50,3 +50,20 @@ protection requires review and passing checks.
5050packaging policy, secrets, licence consistency and workflow security.
5151. Security issues: follow `+SECURITY.md+` — report privately, never in a
5252public issue.
53+
54+ == Signed commits
55+
56+ Every commit that reaches the default branch must be signed; a ruleset refuses
57+ unsigned pushes. Estate policy:
58+ https://github.com/hyperpolymath/standards/blob/main/docs/SIGNING-POLICY.adoc[SIGNING-POLICY].
59+
60+ * **People and interactive agents** sign with an SSH key registered on GitHub
61+ as a *signing* key (`gpg.format=ssh`, `user.signingkey=<key>.pub`,
62+ `commit.gpgsign=true`). The committer email must be verified on that account.
63+ * **Apps, bots and workflows** never `git push` local commits. They write
64+ through the API (`createCommitOnBranch` or the estate `signed-push` action)
65+ so that GitHub signs each commit.
66+ * Merge PRs with **squash**. The ruleset checks every commit on the PR branch,
67+ not just the result, so one unsigned commit blocks the merge. Re-create such a
68+ branch with signed commits (`git cherry-pick -S`) and open a new PR.
69+ Rebase-merge replays commits unsigned and is disabled.
You can’t perform that action at this time.
0 commit comments