Skip to content

Latest commit

 

History

History
37 lines (28 loc) · 1.35 KB

File metadata and controls

37 lines (28 loc) · 1.35 KB

Contributing

Contributions are welcome! Please:

  1. Fork the repository

  2. Create a feature branch from main

  3. Ensure all CI checks pass

  4. Submit a pull request

Standards

This project follows the Rhodium Standard Repository (RSR) conventions.

License

By contributing, you agree that your contributions will be licensed under MPL-2.0 (with MPL-2.0 as automatic legal fallback).

Signed commits

Every commit that reaches the default branch must be signed; a ruleset refuses unsigned pushes. Estate policy: SIGNING-POLICY.

  • People and interactive agents sign with an SSH key registered on GitHub as a signing key (gpg.format=ssh, user.signingkey=<key>.pub, commit.gpgsign=true). The committer email must be verified on that account.

  • Apps, bots and workflows never git push local commits. They write through the API (createCommitOnBranch or the estate signed-push action) so that GitHub signs each commit.

  • Merge PRs with squash. The ruleset checks every commit on the PR branch, not just the result, so one unsigned commit blocks the merge. Re-create such a branch with signed commits (git cherry-pick -S) and open a new PR. Rebase-merge replays commits unsigned and is disabled.