docs: add Signed commits section to CONTRIBUTING - #3
Conversation
Owner ruling D218. See docs/SIGNING-POLICY.adoc in hyperpolymath/standards. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01WRvDivYwLSeVCJUrfjic3f
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (2)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📜 Recent review details⏰ Context from checks skipped due to timeout. (26)
|
| Layer / File(s) | Summary |
|---|---|
Document signed-commit workflow .github/CONTRIBUTING.md, CONTRIBUTING.adoc |
Both guides explain signing requirements, commit creation methods, and merge constraints for pull requests. |
Priority: ⬇️ Low
Estimated code review effort: 1 (Trivial) | ~5 minutes
Change: Other
Suggested reviewers: {{owner}}
Merge Risk: ⚪ Minimal · up to 3cce5
The signing guidance matches the repository’s active signature checks. Rebase availability remains unconfirmed in the live settings; no concrete merge-blocking issue is established.
Security Architecture Review
Security architecture risk: 🔵 Low · up to 3cce5
This changes contributor guidance, not enforcement or privileges. No new bypass is established, but effective signing enforcement and merge restrictions remain insufficiently verified to treat the documented guarantees as confirmed.
Retained concerns
No architecture-level concerns identified.
Security review details
Security Blast Radius
- inferred — The identified policy boundary is acceptance of contributor commits into this repository’s default-branch source history. The inspected change does not expand that boundary through new service callers, execution paths, or granted authority.
Trust Boundaries and Controls
- inferred — The guides’ unconditional signing assurance and statement that rebase merging is disabled cannot be validated from repository files alone. The settings permit rebase, while the ruleset payload specifies squash-only merging; effective behavior depends on deployed controls. This uncertainty does not establish an unsigned-commit attack path.
Hardening Proposals
- proposed — Validate active default-branch rules, signing-bypass semantics, and repository merge settings before relying on universal signing and squash-only assurances. This is control-assurance work, not remediation of a demonstrated bypass.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
| Check name | Status | Explanation |
|---|---|---|
| Title check | ✅ Passed | The title clearly identifies the documentation change and matches the main purpose of the pull request. |
| Description check | ✅ Passed | The description clearly explains the purpose, policy context, main changes, and docs-only scope. It does not include the template sections for the quality checklist, testing, or screenshots, but these… |
| Docstring Coverage | ✅ Passed | No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0… |
| Linked Issues check | ✅ Passed | Check skipped because no linked issues were found for this pull request. |
| Out of Scope Changes check | ✅ Passed | Check skipped because no linked issues were found for this pull request. |
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
- Commit to this branch
- Create a new PR
- Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts
Autopilot is currently an internal CodeRabbit preview.
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.
A rabbit checks each commit with care,
Signed SSH keys hop through the air.
Squash-merged branches cross the gate,
Unsigned commits must recreate.
The guide now shows the signing way.
Comment @coderabbitai help to get the list of available commands.
Adds a Signed commits section to this repo's CONTRIBUTING, per owner ruling D218. The estate policy is
docs/SIGNING-POLICY.adocin hyperpolymath/standards.This repo's default branch is covered by the zero-bypass
Require-Signed-Commitsruleset, and rebase-merge is off. The section tells contributors what that requires:If the file already had its own signing section, that section is replaced in place instead of adding a second one. Lines elsewhere that told people to sign with GPG are changed to match the policy (SSH for people).
This is a docs-only change. The commit was created through
createCommitOnBranch, so GitHub signs it.🤖 Generated with Claude Code
https://claude.ai/code/session_01WRvDivYwLSeVCJUrfjic3f