Skip to content

Commit d46a635

Browse files
hyperpolymathclaudeCopilot
authored
docs: add Signed commits section to CONTRIBUTING (#125)
Adds a **Signed commits** section to this repo's CONTRIBUTING, per owner ruling **D218**. The estate policy is [`docs/SIGNING-POLICY.adoc`](https://github.com/hyperpolymath/standards/blob/main/docs/SIGNING-POLICY.adoc) in hyperpolymath/standards. This repo's default branch is covered by the zero-bypass `Require-Signed-Commits` ruleset, and rebase-merge is off. The section tells contributors what that requires: - People and interactive agents sign with an SSH signing key. - Apps, bots and workflows write through the API, so GitHub signs their commits. - PRs are merged with squash. If the file already had its own signing section, that section is replaced in place instead of adding a second one. Lines elsewhere that told people to sign with GPG are changed to match the policy (SSH for people). This is a docs-only change. The commit was created through `createCommitOnBranch`, so GitHub signs it. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01WRvDivYwLSeVCJUrfjic3f --------- Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com> Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
1 parent d355a20 commit d46a635

1 file changed

Lines changed: 17 additions & 0 deletions

File tree

‎.github/CONTRIBUTING.md‎

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -119,3 +119,20 @@ Footer: issue reference, e.g. Closes #123
119119
\[optional body\]
120120

121121
\[optional footer\]
122+
123+
### Signed commits
124+
125+
Every commit that reaches the default branch must be signed; a ruleset refuses
126+
unsigned pushes. Estate policy:
127+
[SIGNING-POLICY](https://github.com/hyperpolymath/standards/blob/main/docs/SIGNING-POLICY.adoc).
128+
129+
- **People and interactive agents** sign with an SSH key registered on GitHub
130+
as a *signing* key (`gpg.format=ssh`, `user.signingkey=<key>.pub`,
131+
`commit.gpgsign=true`). The committer email must be verified on that account.
132+
- **Apps, bots and workflows** never `git push` local commits. They write
133+
through the API (`createCommitOnBranch` or the estate `signed-push` action)
134+
so that GitHub signs each commit.
135+
- Merge PRs with **squash**. GitHub signs the resulting squash commit, and the
136+
PR's individual commits do not reach the protected default branch.
137+
Contributors should still sign their own commits as required by estate policy.
138+
Rebase-merge replays commits unsigned and is disabled.

0 commit comments

Comments
 (0)