From c5d7909f1d5004f8606d7aff4303f22b0aa58338 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Thu, 1 Oct 2026 07:56:49 +0100 Subject: [PATCH 1/2] docs: add Signed commits section to CONTRIBUTING Owner ruling D218. See docs/SIGNING-POLICY.adoc in hyperpolymath/standards. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01WRvDivYwLSeVCJUrfjic3f --- .github/CONTRIBUTING.md | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) diff --git a/.github/CONTRIBUTING.md b/.github/CONTRIBUTING.md index b4e653c..92ee7a3 100644 --- a/.github/CONTRIBUTING.md +++ b/.github/CONTRIBUTING.md @@ -119,3 +119,20 @@ Footer: issue reference, e.g. Closes #123 \[optional body\] \[optional footer\] + +### Signed commits + +Every commit that reaches the default branch must be signed; a ruleset refuses +unsigned pushes. Estate policy: +[SIGNING-POLICY](https://github.com/hyperpolymath/standards/blob/main/docs/SIGNING-POLICY.adoc). + +- **People and interactive agents** sign with an SSH key registered on GitHub + as a *signing* key (`gpg.format=ssh`, `user.signingkey=.pub`, + `commit.gpgsign=true`). The committer email must be verified on that account. +- **Apps, bots and workflows** never `git push` local commits. They write + through the API (`createCommitOnBranch` or the estate `signed-push` action) + so that GitHub signs each commit. +- Merge PRs with **squash**. The ruleset checks every commit on the PR branch, + not just the result, so one unsigned commit blocks the merge. Re-create such a + branch with signed commits (`git cherry-pick -S`) and open a new PR. + Rebase-merge replays commits unsigned and is disabled. From 6b972d24c60ce886521f87871d22a57d2eabe481 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Thu, 1 Oct 2026 21:13:48 +0100 Subject: [PATCH 2/2] Update .github/CONTRIBUTING.md Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com> --- .github/CONTRIBUTING.md | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/.github/CONTRIBUTING.md b/.github/CONTRIBUTING.md index 92ee7a3..4d606d0 100644 --- a/.github/CONTRIBUTING.md +++ b/.github/CONTRIBUTING.md @@ -129,10 +129,11 @@ unsigned pushes. Estate policy: - **People and interactive agents** sign with an SSH key registered on GitHub as a *signing* key (`gpg.format=ssh`, `user.signingkey=.pub`, `commit.gpgsign=true`). The committer email must be verified on that account. -- **Apps, bots and workflows** never `git push` local commits. They write +- **Apps, bots and workflows** never `git push` local commits to the GitHub + default branch. They write those commits through the API (`createCommitOnBranch` or the estate `signed-push` action) so that GitHub signs each commit. - Merge PRs with **squash**. The ruleset checks every commit on the PR branch, - not just the result, so one unsigned commit blocks the merge. Re-create such a - branch with signed commits (`git cherry-pick -S`) and open a new PR. + not just the result, so one unsigned commit blocks the merge. Re-create such + a branch with signed commits (`git cherry-pick -S`) and open a new PR. Rebase-merge replays commits unsigned and is disabled.