From 965c69705cb4bc8c5a32d8604cb885bf742fbff9 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Wed, 30 Sep 2026 16:29:53 +0100 Subject: [PATCH 1/4] docs: add Signed commits section to CONTRIBUTING Owner ruling D218. See docs/SIGNING-POLICY.adoc in hyperpolymath/standards. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01WRvDivYwLSeVCJUrfjic3f --- .github/CONTRIBUTING.md | 16 ++++++++++++++++ CONTRIBUTING.adoc | 16 ++++++++++++++++ 2 files changed, 32 insertions(+) diff --git a/.github/CONTRIBUTING.md b/.github/CONTRIBUTING.md index d310fec..96d2dfb 100644 --- a/.github/CONTRIBUTING.md +++ b/.github/CONTRIBUTING.md @@ -5,3 +5,19 @@ at the repository root (estate policy: AsciiDoc by default). This `.github/` copy exists only so GitHub surfaces a pointer on the issue/PR templates; edit the root AsciiDoc guide, not this file. + +## Signed Commits + +Every commit that reaches the default branch must be signed; a ruleset refuses +unsigned pushes. Estate policy: +[SIGNING-POLICY](https://github.com/hyperpolymath/standards/blob/main/docs/SIGNING-POLICY.adoc). + +- **People and interactive agents** sign with an SSH key registered on GitHub + as a *signing* key (`gpg.format=ssh`, `commit.gpgsign=true`). The committer + email must be verified on that account. +- **Apps, bots and workflows** never `git push` local commits. They write + through the API (`createCommitOnBranch`, the estate `signed-push` action, or a + squash merge) so that GitHub signs the commit. +- Merge PRs with **squash**. Rebase-merge replays commits unsigned and is + disabled. + diff --git a/CONTRIBUTING.adoc b/CONTRIBUTING.adoc index 6649aed..4099293 100644 --- a/CONTRIBUTING.adoc +++ b/CONTRIBUTING.adoc @@ -141,3 +141,19 @@ Include: == License All contributions are licensed under MPL-2.0. + +== Signed commits + +Every commit that reaches the default branch must be signed; a ruleset refuses +unsigned pushes. Estate policy: +https://github.com/hyperpolymath/standards/blob/main/docs/SIGNING-POLICY.adoc[SIGNING-POLICY]. + +* **People and interactive agents** sign with an SSH key registered on GitHub + as a *signing* key (`gpg.format=ssh`, `commit.gpgsign=true`). The committer + email must be verified on that account. +* **Apps, bots and workflows** never `git push` local commits. They write + through the API (`createCommitOnBranch`, the estate `signed-push` action, or a + squash merge) so that GitHub signs the commit. +* Merge PRs with **squash**. Rebase-merge replays commits unsigned and is + disabled. + From dbda71e2cb5f2f46d2994fb53e1d407dcf022e07 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Wed, 30 Sep 2026 17:22:03 +0100 Subject: [PATCH 2/4] docs: tidy Signed commits section Owner ruling D218. See docs/SIGNING-POLICY.adoc in hyperpolymath/standards. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01WRvDivYwLSeVCJUrfjic3f --- .github/CONTRIBUTING.md | 1 - CONTRIBUTING.adoc | 1 - 2 files changed, 2 deletions(-) diff --git a/.github/CONTRIBUTING.md b/.github/CONTRIBUTING.md index 96d2dfb..a27ba1a 100644 --- a/.github/CONTRIBUTING.md +++ b/.github/CONTRIBUTING.md @@ -20,4 +20,3 @@ unsigned pushes. Estate policy: squash merge) so that GitHub signs the commit. - Merge PRs with **squash**. Rebase-merge replays commits unsigned and is disabled. - diff --git a/CONTRIBUTING.adoc b/CONTRIBUTING.adoc index 4099293..15341a8 100644 --- a/CONTRIBUTING.adoc +++ b/CONTRIBUTING.adoc @@ -156,4 +156,3 @@ https://github.com/hyperpolymath/standards/blob/main/docs/SIGNING-POLICY.adoc[SI squash merge) so that GitHub signs the commit. * Merge PRs with **squash**. Rebase-merge replays commits unsigned and is disabled. - From c9b2bb3486b7bc58da36a1274fde6d6554a7f221 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Wed, 30 Sep 2026 23:26:15 +0100 Subject: [PATCH 3/4] docs: correct Signed commits section Owner ruling D218. See docs/SIGNING-POLICY.adoc in hyperpolymath/standards. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01WRvDivYwLSeVCJUrfjic3f --- .github/CONTRIBUTING.md | 12 +++++++----- CONTRIBUTING.adoc | 10 ++++++---- 2 files changed, 13 insertions(+), 9 deletions(-) diff --git a/.github/CONTRIBUTING.md b/.github/CONTRIBUTING.md index a27ba1a..2264260 100644 --- a/.github/CONTRIBUTING.md +++ b/.github/CONTRIBUTING.md @@ -6,7 +6,7 @@ at the repository root (estate policy: AsciiDoc by default). This `.github/` copy exists only so GitHub surfaces a pointer on the issue/PR templates; edit the root AsciiDoc guide, not this file. -## Signed Commits +## Signed commits Every commit that reaches the default branch must be signed; a ruleset refuses unsigned pushes. Estate policy: @@ -16,7 +16,9 @@ unsigned pushes. Estate policy: as a *signing* key (`gpg.format=ssh`, `commit.gpgsign=true`). The committer email must be verified on that account. - **Apps, bots and workflows** never `git push` local commits. They write - through the API (`createCommitOnBranch`, the estate `signed-push` action, or a - squash merge) so that GitHub signs the commit. -- Merge PRs with **squash**. Rebase-merge replays commits unsigned and is - disabled. + through the API (`createCommitOnBranch` or the estate `signed-push` action) + so that GitHub signs each commit. +- Merge PRs with **squash**. The ruleset checks every commit on the PR branch, + not just the result, so one unsigned commit blocks the merge. Re-create such a + branch with signed commits (`git cherry-pick -S`) and open a new PR. + Rebase-merge replays commits unsigned and is disabled. diff --git a/CONTRIBUTING.adoc b/CONTRIBUTING.adoc index 15341a8..42509cf 100644 --- a/CONTRIBUTING.adoc +++ b/CONTRIBUTING.adoc @@ -152,7 +152,9 @@ https://github.com/hyperpolymath/standards/blob/main/docs/SIGNING-POLICY.adoc[SI as a *signing* key (`gpg.format=ssh`, `commit.gpgsign=true`). The committer email must be verified on that account. * **Apps, bots and workflows** never `git push` local commits. They write - through the API (`createCommitOnBranch`, the estate `signed-push` action, or a - squash merge) so that GitHub signs the commit. -* Merge PRs with **squash**. Rebase-merge replays commits unsigned and is - disabled. + through the API (`createCommitOnBranch` or the estate `signed-push` action) + so that GitHub signs each commit. +* Merge PRs with **squash**. The ruleset checks every commit on the PR branch, + not just the result, so one unsigned commit blocks the merge. Re-create such a + branch with signed commits (`git cherry-pick -S`) and open a new PR. + Rebase-merge replays commits unsigned and is disabled. From 204787de10aa1f029e224e9fa2f7e3e4103bfbd0 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Thu, 1 Oct 2026 09:29:33 +0100 Subject: [PATCH 4/4] docs: align Signed commits section with SSH-for-people and heading level Owner ruling D218. See docs/SIGNING-POLICY.adoc in hyperpolymath/standards. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01WRvDivYwLSeVCJUrfjic3f --- .github/CONTRIBUTING.md | 4 ++-- CONTRIBUTING.adoc | 4 ++-- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/.github/CONTRIBUTING.md b/.github/CONTRIBUTING.md index 2264260..2117374 100644 --- a/.github/CONTRIBUTING.md +++ b/.github/CONTRIBUTING.md @@ -13,8 +13,8 @@ unsigned pushes. Estate policy: [SIGNING-POLICY](https://github.com/hyperpolymath/standards/blob/main/docs/SIGNING-POLICY.adoc). - **People and interactive agents** sign with an SSH key registered on GitHub - as a *signing* key (`gpg.format=ssh`, `commit.gpgsign=true`). The committer - email must be verified on that account. + as a *signing* key (`gpg.format=ssh`, `user.signingkey=.pub`, + `commit.gpgsign=true`). The committer email must be verified on that account. - **Apps, bots and workflows** never `git push` local commits. They write through the API (`createCommitOnBranch` or the estate `signed-push` action) so that GitHub signs each commit. diff --git a/CONTRIBUTING.adoc b/CONTRIBUTING.adoc index 42509cf..c2539c4 100644 --- a/CONTRIBUTING.adoc +++ b/CONTRIBUTING.adoc @@ -149,8 +149,8 @@ unsigned pushes. Estate policy: https://github.com/hyperpolymath/standards/blob/main/docs/SIGNING-POLICY.adoc[SIGNING-POLICY]. * **People and interactive agents** sign with an SSH key registered on GitHub - as a *signing* key (`gpg.format=ssh`, `commit.gpgsign=true`). The committer - email must be verified on that account. + as a *signing* key (`gpg.format=ssh`, `user.signingkey=.pub`, + `commit.gpgsign=true`). The committer email must be verified on that account. * **Apps, bots and workflows** never `git push` local commits. They write through the API (`createCommitOnBranch` or the estate `signed-push` action) so that GitHub signs each commit.