File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change @@ -119,3 +119,20 @@ Footer: issue reference, e.g. Closes #123
119119\[ optional body\]
120120
121121\[ optional footer\]
122+
123+ ### Signed commits
124+
125+ Every commit that reaches the default branch must be signed; a ruleset refuses
126+ unsigned pushes. Estate policy:
127+ [ SIGNING-POLICY] ( https://github.com/hyperpolymath/standards/blob/main/docs/SIGNING-POLICY.adoc ) .
128+
129+ - ** People and interactive agents** sign with an SSH key registered on GitHub
130+ as a * signing* key (` gpg.format=ssh ` , ` user.signingkey=<key>.pub ` ,
131+ ` commit.gpgsign=true ` ). The committer email must be verified on that account.
132+ - ** Apps, bots and workflows** never ` git push ` local commits. They write
133+ through the API (` createCommitOnBranch ` or the estate ` signed-push ` action)
134+ so that GitHub signs each commit.
135+ - Merge PRs with ** squash** . The ruleset checks every commit on the PR branch,
136+ not just the result, so one unsigned commit blocks the merge. Re-create such a
137+ branch with signed commits (` git cherry-pick -S ` ) and open a new PR.
138+ Rebase-merge replays commits unsigned and is disabled.
You can’t perform that action at this time.
0 commit comments