From d378063bbde9e41d655a2e7b3747706214432280 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Wed, 30 Sep 2026 23:22:49 +0100 Subject: [PATCH 1/3] docs: add Signed commits section to CONTRIBUTING Owner ruling D218. See docs/SIGNING-POLICY.adoc in hyperpolymath/standards. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01WRvDivYwLSeVCJUrfjic3f --- .github/CONTRIBUTING.md | 15 +++++++++++++++ 1 file changed, 15 insertions(+) diff --git a/.github/CONTRIBUTING.md b/.github/CONTRIBUTING.md index bc3ef65..9aa7565 100644 --- a/.github/CONTRIBUTING.md +++ b/.github/CONTRIBUTING.md @@ -26,3 +26,18 @@ Copyright (c) Jonathan D.A. Jewell ## License Contributions licensed under project license. + +## Signed Commits + +Every commit that reaches the default branch must be signed; a ruleset refuses +unsigned pushes. Estate policy: +[SIGNING-POLICY](https://github.com/hyperpolymath/standards/blob/main/docs/SIGNING-POLICY.adoc). + +- **People and interactive agents** sign with an SSH key registered on GitHub + as a *signing* key (`gpg.format=ssh`, `commit.gpgsign=true`). The committer + email must be verified on that account. +- **Apps, bots and workflows** never `git push` local commits. They write + through the API (`createCommitOnBranch`, the estate `signed-push` action, or a + squash merge) so that GitHub signs the commit. +- Merge PRs with **squash**. Rebase-merge replays commits unsigned and is + disabled. From a9b68f527b967f7f02d1eaed321f52c010a227d7 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Wed, 30 Sep 2026 23:27:14 +0100 Subject: [PATCH 2/3] docs: correct Signed commits section Owner ruling D218. See docs/SIGNING-POLICY.adoc in hyperpolymath/standards. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01WRvDivYwLSeVCJUrfjic3f --- .github/CONTRIBUTING.md | 12 +++++++----- 1 file changed, 7 insertions(+), 5 deletions(-) diff --git a/.github/CONTRIBUTING.md b/.github/CONTRIBUTING.md index 9aa7565..e2a530b 100644 --- a/.github/CONTRIBUTING.md +++ b/.github/CONTRIBUTING.md @@ -27,7 +27,7 @@ Copyright (c) Jonathan D.A. Jewell Contributions licensed under project license. -## Signed Commits +## Signed commits Every commit that reaches the default branch must be signed; a ruleset refuses unsigned pushes. Estate policy: @@ -37,7 +37,9 @@ unsigned pushes. Estate policy: as a *signing* key (`gpg.format=ssh`, `commit.gpgsign=true`). The committer email must be verified on that account. - **Apps, bots and workflows** never `git push` local commits. They write - through the API (`createCommitOnBranch`, the estate `signed-push` action, or a - squash merge) so that GitHub signs the commit. -- Merge PRs with **squash**. Rebase-merge replays commits unsigned and is - disabled. + through the API (`createCommitOnBranch` or the estate `signed-push` action) + so that GitHub signs each commit. +- Merge PRs with **squash**. The ruleset checks every commit on the PR branch, + not just the result, so one unsigned commit blocks the merge. Re-create such a + branch with signed commits (`git cherry-pick -S`) and open a new PR. + Rebase-merge replays commits unsigned and is disabled. From cf8f5843b1dce0ad4d91e2b2ee73e9fafa3481bf Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Thu, 1 Oct 2026 00:06:29 +0100 Subject: [PATCH 3/3] docs: align Signed commits section with SSH-for-people and heading level Owner ruling D218. See docs/SIGNING-POLICY.adoc in hyperpolymath/standards. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01WRvDivYwLSeVCJUrfjic3f --- .github/CONTRIBUTING.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/CONTRIBUTING.md b/.github/CONTRIBUTING.md index e2a530b..2002d58 100644 --- a/.github/CONTRIBUTING.md +++ b/.github/CONTRIBUTING.md @@ -34,8 +34,8 @@ unsigned pushes. Estate policy: [SIGNING-POLICY](https://github.com/hyperpolymath/standards/blob/main/docs/SIGNING-POLICY.adoc). - **People and interactive agents** sign with an SSH key registered on GitHub - as a *signing* key (`gpg.format=ssh`, `commit.gpgsign=true`). The committer - email must be verified on that account. + as a *signing* key (`gpg.format=ssh`, `user.signingkey=.pub`, + `commit.gpgsign=true`). The committer email must be verified on that account. - **Apps, bots and workflows** never `git push` local commits. They write through the API (`createCommitOnBranch` or the estate `signed-push` action) so that GitHub signs each commit.